VDB

TNCVE-2026-3108

TNCVE-2026-3108 PUBLISHED

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences that enable screen manipulation, fake prompts, and clipboard hijacking.. Mattermost Advisory ID: MMSA-2026-00599

Timeline

  • Mar 26, 2026 CVE Published

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›