Mattermost has CSRF vulnerability via Calls Widget page in github.com/mattermost/mattermost-plugin-calls
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-4254" }
"https://vuln.go.dev/ID/GO-2025-4254.json"