VDB
GO-2025-3731
GO-2025-3731
PUBLISHED
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | mattermost/mattermost/server/v8 | 0, 0 |
| github.com | mattermost/mattermost-server/v6 | 0, 0 |
| github.com | mattermost/mattermost-server | 10.0.0-rc1+incompatible, 10.6.0-rc1+incompatible, 10.7.0-rc1+incompatible |
| github.com | mattermost/mattermost-server/v5 | 0, 0 |
Timeline
- Jun 3, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory