Token Negotiation Vulnerability in Mattermost by Mattermost, Inc.
CVE-2025-6227

2.2LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
18 July 2025

What is CVE-2025-6227?

Certain versions of Mattermost, specifically 10.5.x up to and including 10.5.7 and 9.11.x up to and including 9.11.16, exhibit a vulnerability where the application fails to negotiate a new token during the invitation process. This loophole could potentially enable an adversarial user, who has access to both the invitation and associated credentials, to execute synchronization payloads within the original server via the REST API, potentially compromising the application's integrity.

Affected Version(s)

Mattermost 10.5.0 <= 10.5.7

Mattermost 9.11.0 <= 9.11.16

Mattermost 10.9.0

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel de la Cruz
.
CVE-2025-6227 : Token Negotiation Vulnerability in Mattermost by Mattermost, Inc.