Mattermost has CSRF vulnerability via Calls Widget page in github.com/mattermost/mattermost-plugin-calls
{ "url": "https://pkg.go.dev/vuln/GO-2025-4254", "review_status": "UNREVIEWED" }