← Back

CVE-2025-13324

nvd nist
Published: Dec 17, 2025Modified: Dec 29, 2025

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.2 / Impact: 1.4
Source: responsibledisclosure@mattermost.com (Secondary)

Description

Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed.

Affected (3)

1 product
Mattermost Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mattermost
From 10.11.0 to 10.11.6
From 10.12.0 to 10.12.3
From 11.0.0 to 11.0.5

References (1)

Source: responsibledisclosure@mattermost.com
Vendor Advisory

Timeline

No history available yet.