CVE-2026-13426: Client4 fails to validate path parameters
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID: MMSA-2025-00532
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
github.com/mattermost/mattermost/server/publicto a version that resolves this vulnerability.Fixed in v0.1.22Patch MMSA-2025-00532
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13426?
The severity of CVE-2026-13426 is rated as medium with a score of 5.4.
How do I fix CVE-2026-13426?
To fix CVE-2026-13426, upgrade the Mattermost server/public module to version 0.1.22 or later.
What type of vulnerability is CVE-2026-13426?
CVE-2026-13426 is categorized as a Path Traversal vulnerability.
What impact does CVE-2026-13426 have?
CVE-2026-13426 can allow attackers to redirect API calls to unintended endpoints using crafted IDs.
Which versions of Mattermost are affected by CVE-2026-13426?
Mattermost versions prior to v0.1.22 are affected by CVE-2026-13426.