PT-2025-52873 · Atlassian+1 · Jira Plugin+1

Juho Forsén

·

Published

2025-12-24

·

Updated

2026-03-03

·

CVE-2025-64641

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.11.x through 10.11.7 Mattermost versions 10.12.x through 10.12.3 Mattermost versions 11.0.x through 11.0.5 Mattermost versions 11.1.x through 11.1.0
Description Mattermost fails to verify that post actions invoking '/share-issue-publicly' were created by the Jira plugin. This allows a malicious Mattermost user to potentially exfiltrate Jira tickets when victim users interact with affected posts.
Recommendations Update Mattermost to a version later than 10.11.7. Update Mattermost to a version later than 10.12.3. Update Mattermost to a version later than 11.0.5. Update Mattermost to a version later than 11.1.0.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-64641
GHSA-VWW6-79RV-3J4X
GO-2025-4260
SUSE-SU-2026:0757-1

Affected Products

Jira Plugin
Mattermost