Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channelid}/commonteams endpoint
{
"nvd_published_at": "2025-11-27T17:15:46Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed_at": "2025-12-01T23:57:02Z"
}