CVE-2023-2808: Mattermost
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.
Affected products
- Mattermost Mattermost: from 5.34.0, before 7.1.9 (fixed in 7.1.9); from 7.2.0, before 7.8.4 (fixed in 7.8.4); from 7.9.0, before 7.9.3 (fixed in 7.9.3)
Published 2023-05-29. Last modified 2026-06-17.