GHSA-3g36-gf7c-75qw
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Quick fix
GHSA-3g36-gf7c-75qw — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v8.0.0-20250218121836-2b5275d87136Details
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.
Are you affected?
Enter the version of the package you're using.
Affected packages
2.0.0No fixed version published yet for github.com/mattermost/mattermost-plugin-playbooks (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 8.0.0-20250218121836-2b5275d87136go get github.com/mattermost/mattermost/server/v8@v8.0.0-20250218121836-2b5275d8713610.4.0No fixed version published yet for github.com/mattermost/mattermost/server/v8 (go modules). Pin to a known-safe version or switch to an alternative.
10.5.0No fixed version published yet for github.com/mattermost/mattermost/server/v8 (go modules). Pin to a known-safe version or switch to an alternative.
9.11.0No fixed version published yet for github.com/mattermost/mattermost/server/v8 (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 1.41.0go get github.com/mattermost/mattermost-plugin-playbooks@v1.41.0References
- https://nvd.nist.gov/vuln/detail/CVE-2025-41395[ADVISORY]
- https://github.com/mattermost/mattermost-plugin-playbooks/commit/4c823090e281cb9c0d5c17ee2e5db275117540d1[WEB]
- https://github.com/mattermost/mattermost/commit/2b5275d87136f07e016c8eca09a2f004b31afc8a[WEB]
- https://github.com/mattermost/mattermost-plugin-playbooks[PACKAGE]
- https://mattermost.com/security-updates[WEB]