Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1777.json"