CVE-2025-14350: Information disclosure via channel mentions in posts
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channelmentions property in the API response. Mattermost Advisory ID: MMSA-2025-00563
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14350?
CVE-2025-14350 is classified as a medium severity vulnerability.
How do I fix CVE-2025-14350?
To fix CVE-2025-14350, update Mattermost to versions 11.1.3 or later, 10.11.10 or later, or 11.2.2 or later.
What kind of data is exposed by CVE-2025-14350?
CVE-2025-14350 allows authenticated users to determine the existence of teams and their URL names.
Which versions of Mattermost are affected by CVE-2025-14350?
Mattermost versions 11.1.x up to 11.1.2, 10.11.x up to 10.11.9, and 11.2.x up to 11.2.1 are affected by CVE-2025-14350.
What is the impact of CVE-2025-14350 on users?
The impact of CVE-2025-14350 is that it can lead to unintended information disclosure regarding team memberships.