Token Negotiation Vulnerability in Mattermost by Mattermost, Inc.
CVE-2025-6227
What is CVE-2025-6227?
Certain versions of Mattermost, specifically 10.5.x up to and including 10.5.7 and 9.11.x up to and including 9.11.16, exhibit a vulnerability where the application fails to negotiate a new token during the invitation process. This loophole could potentially enable an adversarial user, who has access to both the invitation and associated credentials, to execute synchronization payloads within the original server via the REST API, potentially compromising the application's integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.7
Mattermost 9.11.0 <= 9.11.16
Mattermost 10.9.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved