github.com/mattermost/mattermost-plugin-github
Activity
- Latest release
- 6y ago
- Total releases
- 18
- Cadence
- ~35 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Aug 09, 2018
| Version | Released | |
|---|---|---|
v1.0.0
major
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (8)
|
|
v0.14.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.14.0
minor
Dependencies (6)
|
|
v0.13.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (6)
|
|
v0.12.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.0
minor
Dependencies (7)
|
|
v0.11.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.11.0
minor
Dependencies (7)
|
|
v0.10.2
patch
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.10.2
patch
Dependencies (5)
|
|
v0.10.1
patch
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.10.1
patch
Dependencies (5)
|
|
v0.9.2
patch
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.9.2
patch
|
|
v0.10.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.10.0
minor
Dependencies (5)
|
|
v0.9.1
patch
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.9.1
patch
|
|
v0.9.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.9.0
minor
|
|
v0.8.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.0
minor
|
|
v0.7.1
patch
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.1
patch
|
|
v0.7.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.0
minor
|
|
v0.6.2
patch
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.2
patch
|
|
v0.6.1
patch
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.1
patch
|
|
v0.6.0
minor
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.0
minor
|
|
v0.0.1
initial
4 CVEs
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260330164815-c2840e980b3c
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260410143745-9b41b1fd43c4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
1.0.1-0.20260318132218-6e6b740c4852
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. Fixed in
1.0.1-0.20250829075715-0deffcfc6bee
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.0.1
initial
|