Executive brief
The Mattermost Google Drive plugin, which allows users to share and manage files within the Mattermost collaboration platform, contains a security flaw in how it handles file sharing. An authenticated user could exploit this to share files into private channels they are not members of, potentially revealing the existence of those private channels. This could lead to unauthorized information disclosure and a breach of internal communication privacy.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Mattermost Google Drive plugin's file creation endpoint. The component fails to verify if the requesting user is a member of the target channel before processing a file-sharing request. An authenticated attacker with a connected Google account can exploit this over the network to post Google Drive files to private channels they do not belong to, which also confirms the existence of those channels. The attack requires a low-privileged account but is considered high complexity due to the need for a connected Google account and knowledge of target channel identifiers. The issue is resolved in version 1.1.0.
Affected products
- Mattermost Google Drive Plugin < 1.1.0
Timeline
- 2026-03-05: patched: Version 1.1.0 released on GitHub.
- 2026-06-25: disclosed: CVE published to NVD.