API Access Control Issues in Mattermost Product by Mattermost
CVE-2025-4128
3.1LOW
What is CVE-2025-4128?
The Mattermost communication platform is vulnerable due to improper access control in its API. Specifically, team information can be accessed by guest users who are not members of public teams, through direct API calls to the endpoint /api/v4/teams/{team_id}. This flaw allows unauthorized disclosure of sensitive information, potentially leading to data leaks and undermining team privacy.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.4
Mattermost 9.11.0 <= 9.11.13
Mattermost 10.8.0