CVE-2025-1792: Mattermost Server
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
Affected products
- Mattermost Mattermost Server: from 9.11.0, before 9.11.13 (fixed in 9.11.13); from 10.5.0, before 10.5.4 (fixed in 10.5.4); from 10.7.0, before 10.7.1 (fixed in 10.7.1)
Published 2025-05-30. Last modified 2026-06-17.