GHSA-jx93-pf6x-874r

Suggest an improvement
Source
https://github.com/advisories/GHSA-jx93-pf6x-874r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jx93-pf6x-874r/GHSA-jx93-pf6x-874r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jx93-pf6x-874r
Aliases
Published
2026-05-18T09:31:47Z
Modified
2026-06-25T23:11:43Z
Severity
  • 3.8 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Mattermost doesn't escape some variables that could contain malicious content during error page composition
Details

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-01T15:00:03Z",
    "nvd_published_at":  "2026-05-18T08:16:13Z",
    "severity":  "LOW"
}
References

Affected packages

Go
github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.11.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jx93-pf6x-874r/GHSA-jx93-pf6x-874r.json"
github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
11.5.0
Fixed
11.5.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jx93-pf6x-874r/GHSA-jx93-pf6x-874r.json"
github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.0.0-20260310115442-5a1ea95044d

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jx93-pf6x-874r/GHSA-jx93-pf6x-874r.json"
github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.3.2-0.20260310115442-5a1ea95044dc

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jx93-pf6x-874r/GHSA-jx93-pf6x-874r.json"