Token Negotiation Vulnerability in Mattermost by Mattermost, Inc.
CVE-2025-6227
2.2LOW
What is CVE-2025-6227?
Certain versions of Mattermost, specifically 10.5.x up to and including 10.5.7 and 9.11.x up to and including 9.11.16, exhibit a vulnerability where the application fails to negotiate a new token during the invitation process. This loophole could potentially enable an adversarial user, who has access to both the invitation and associated credentials, to execute synchronization payloads within the original server via the REST API, potentially compromising the application's integrity.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.7
Mattermost 9.11.0 <= 9.11.16
Mattermost 10.9.0