GHSA-689c-xq7x-xjwf
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Quick fix
GHSA-689c-xq7x-xjwf — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v8.0.0-20250218121836-2b5275d87136Details
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 8.0.0-20250218121836-2b5275d87136go get github.com/mattermost/mattermost/server/v8@v8.0.0-20250218121836-2b5275d871362.0.0No fixed version published yet for github.com/mattermost/mattermost-plugin-playbooks (go modules). Pin to a known-safe version or switch to an alternative.
10.4.0No fixed version published yet for github.com/mattermost/mattermost/server/v8 (go modules). Pin to a known-safe version or switch to an alternative.
10.5.0No fixed version published yet for github.com/mattermost/mattermost/server/v8 (go modules). Pin to a known-safe version or switch to an alternative.
9.11.0No fixed version published yet for github.com/mattermost/mattermost/server/v8 (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 1.41.0go get github.com/mattermost/mattermost-plugin-playbooks@v1.41.0References
- https://nvd.nist.gov/vuln/detail/CVE-2025-35965[ADVISORY]
- https://github.com/mattermost/mattermost-plugin-playbooks/commit/bf2633dad09f5768ce2bea4b7c5ffb74050052a8[WEB]
- https://github.com/mattermost/mattermost/commit/2b5275d87136f07e016c8eca09a2f004b31afc8a[WEB]
- https://github.com/mattermost/mattermost-plugin-playbooks[PACKAGE]
- https://mattermost.com/security-updates[WEB]