CVE-2025-4128: Mattermost Server

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.

Affected products

  • Mattermost Mattermost Server: from 9.11.0, before 9.11.14 (fixed in 9.11.14); from 10.5.0, before 10.5.5 (fixed in 10.5.5)

Published 2025-06-11. Last modified 2026-06-17.