← back
CVE-2025-13352lowCWE-1287

Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3epss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
Affected products
Mattermost · Mattermost