Mattermost · Mattermost · CVE-2025-24920
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 9.11.x through 9.11.8
Mattermost versions 10.3.x through 10.3.3
Mattermost versions 10.4.x through 10.4.2
Mattermost versions 10.5.x through 10.5.0
**Description**
The issue allows authenticated users to create or update bookmarks in archived channels, as the affected versions of Mattermost do not properly restrict bookmark creation and updates in such channels.
**Recommendations**
For versions 9.11.x through 9.11.8, update to a version that restricts bookmark creation and updates in archived channels.
For versions 10.3.x through 10.3.3, update to a version that restricts bookmark creation and updates in archived channels.
For versions 10.4.x through 10.4.2, update to a version that restricts bookmark creation and updates in archived channels.
For versions 10.5.x through 10.5.0, update to a version that restricts bookmark creation and updates in archived channels.