Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the github.com/mattermost/mattermost/server/public module to v0.1.22 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Fri, 26 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID: MMSA-2025-00532 | |
| Title | Client4 fails to validate path parameters | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-06-26T14:39:00.126Z
Reserved: 2026-06-26T13:32:10.276Z
Link: CVE-2026-13426
Updated: 2026-06-26T14:38:56.725Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T15:45:02Z