We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-6227

Invite token is used as part of the secure communication



Description

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.

Reserved 2025-06-18 | Published 2025-07-18 | Updated 2025-07-18 | Assigner Mattermost


LOW: 2.2CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-522: Insufficiently Protected Credentials

Product status

Default status
unaffected

10.5.0
affected

9.11.0
affected

10.9.0
unaffected

10.5.8
unaffected

9.11.17
unaffected

Credits

Miguel de la Cruz finder

References

mattermost.com/security-updates

cve.org (CVE-2025-6227)

nvd.nist.gov (CVE-2025-6227)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-6227

Support options

Helpdesk Chat, Email, Knowledgebase