API Endpoint Permission Flaw in Mattermost's Playbooks Plugin
CVE-2025-41423

3.1LOW

Key Information:

Vendor
Mattermost
Vendor
CVE Published:
24 April 2025

Summary

The Mattermost Playbooks plugin contains a critical flaw in its API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread. This vulnerability allows any user, regardless of their channel access or permissions, to delete posts generated by the Playbooks bot. As a result, unauthorized users could disrupt ongoing discussions or workflows by removing key content without the necessary permissions.

Affected Version(s)

Mattermost 10.4.0 <= 10.4.2

Mattermost 10.5.0

Mattermost 9.11.0 <= 9.11.10

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tobias Weisshaar (kun_19)
.