CVE-2024-39361: Mattermost

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined posts

Affected products

  • Mattermost Mattermost: from 9.5.0, before 9.5.6 (fixed in 9.5.6); from 9.6.0, before 9.6.3 (fixed in 9.6.3); from 9.7.0, before 9.7.4 (fixed in 9.7.4); from 9.8.0, before 9.8.1 (fixed in 9.8.1)

Published 2024-07-03. Last modified 2026-06-17.