CVE-2023-2808: Mattermost

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.

Affected products

  • Mattermost Mattermost: from 5.34.0, before 7.1.9 (fixed in 7.1.9); from 7.2.0, before 7.8.4 (fixed in 7.8.4); from 7.9.0, before 7.9.3 (fixed in 7.9.3)

Published 2023-05-29. Last modified 2026-06-17.