GHSA-wvcv-9xpm-7mqc

Suggest an improvement
Source
https://github.com/advisories/GHSA-wvcv-9xpm-7mqc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wvcv-9xpm-7mqc/GHSA-wvcv-9xpm-7mqc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wvcv-9xpm-7mqc
Aliases
Published
2026-05-18T09:31:48Z
Modified
2026-06-25T23:11:29Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
Details

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597

Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-01T15:13:28Z",
    "nvd_published_at":  "2026-05-18T09:16:22Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go
github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
11.5.0
Fixed
11.5.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wvcv-9xpm-7mqc/GHSA-wvcv-9xpm-7mqc.json"
github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.11.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wvcv-9xpm-7mqc/GHSA-wvcv-9xpm-7mqc.json"
github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
11.4.0
Fixed
11.4.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wvcv-9xpm-7mqc/GHSA-wvcv-9xpm-7mqc.json"
github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.0.0-20260306123948-f5fe8ded6b63

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wvcv-9xpm-7mqc/GHSA-wvcv-9xpm-7mqc.json"
github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.3.2-0.20260306123948-f5fe8ded6b63

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wvcv-9xpm-7mqc/GHSA-wvcv-9xpm-7mqc.json"