CVE-2025-13352: Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13352?
CVE-2025-13352 is considered a medium severity vulnerability due to its potential to allow unauthorized actions through the GitHub reaction feature.
How do I fix CVE-2025-13352?
To fix CVE-2025-13352, upgrade Mattermost to version 10.11.7 or later, and update the Mattermost GitHub plugin to version 2.4.1 or later.
What are the vulnerable versions for CVE-2025-13352?
CVE-2025-13352 affects Mattermost versions 10.11.0 to 10.11.6 and Mattermost GitHub plugin versions up to 2.4.0.
What impact does CVE-2025-13352 have on users?
CVE-2025-13352 allows attackers to hijack the GitHub reaction feature, potentially leading to unwanted reactions on arbitrary GitHub objects.
Is there a workaround for CVE-2025-13352?
There are no official workarounds for CVE-2025-13352; the recommended action is to update to the patched versions.