PT-2025-34195 · Mattermost · Mattermost

Juho Forsén

·

Published

2025-08-21

·

Updated

2025-08-29

·

CVE-2025-49810

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost versions 10.5.0 through 10.5.8
Description: Mattermost versions 10.5.x through 10.5.8 do not validate access controls when accessing data, potentially allowing a user to read a thread through AI posts.
Recommendations: Update to a version later than 10.5.8.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49810
GHSA-PWVR-GRQG-7VP2
GO-2025-3903

Affected Products

Mattermost