Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions
{ "github_reviewed_at": "2025-08-21T16:02:16Z", "severity": "LOW", "cwe_ids": [ "CWE-918" ], "nvd_published_at": "2025-08-21T08:15:29Z", "github_reviewed": true }