Junglewise Threat Intelligence
CVE-2025-13352: GO-2025-4247 - Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
CVE-2025-13352 · Severity: low · CVSS 3.1 · Published 2025-12-22
Technologies: github.com/mattermost/mattermost (Go), github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), github.com/mattermost/mattermost-plugin-github (Go), github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go.
Executive brief
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
Affected products
- Go github.com/mattermost/mattermost
- Go github.com/mattermost/mattermost-server/v5
- Go github.com/mattermost/mattermost-server/v6
- Go github.com/mattermost/mattermost-plugin-github
- Go github.com/mattermost/mattermost/server/v8
- Go github.com/mattermost/mattermost-server