VDB

CVE-2025-13352

CVE-2025-13352 PUBLISHED CVSS 3 LOW

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.

EPSS 0.18% · 6.2th percentile

Risk Scores

CVSS 3.1
3
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
EPSS Score
0.18%
6.2th percentile

Affected Products

VendorProductVersions
github.commattermost/mattermost/server/v810.11.0-rc1
github.commattermost/mattermost11.0.0-alpha.1, 0
mattermostmattermost_server10.11.0
MattermostMattermost11.1.0, 10.11.7, 10.11.0
github.commattermost/mattermost-plugin-github0

Timeline

  • Nov 18, 2025 CVE ID Reserved
  • Dec 17, 2025 CVE Published
  • Dec 17, 2025 PoC Published
  • Dec 18, 2025 EPSS Score
  • Dec 22, 2025 EPSS Score
  • Dec 26, 2025 EPSS Score
  • Dec 30, 2025 EPSS Score
  • Jan 4, 2026 EPSS Score
  • Jan 8, 2026 EPSS Score
  • Jan 12, 2026 EPSS Score
  • Jan 16, 2026 EPSS Score
  • Jan 20, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›