CVE-2025-12559: Information Disclosure in Common Teams API
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channelid}/commonteams endpoint
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12559?
CVE-2025-12559 has a medium severity level due to the potential exposure of sensitive email addresses.
How do I fix CVE-2025-12559?
To fix CVE-2025-12559, upgrade your Mattermost installation to version 11.0.3 or later, or 10.12.2 or later.
What are the affected versions of Mattermost for CVE-2025-12559?
Affected versions for CVE-2025-12559 are Mattermost 11.0.x up to 11.0.2, 10.12.x up to 10.12.1, 10.11.x up to 10.11.4, and 10.5.x up to 10.5.12.
What type of data is exposed in CVE-2025-12559?
CVE-2025-12559 allows authenticated users to view team email addresses that should only be visible to Team Admins.
Can CVE-2025-12559 be exploited without authentication?
No, CVE-2025-12559 requires an authenticated user to exploit the vulnerability.