Executive brief
Mattermost, a collaboration and messaging platform, contains a vulnerability where certain error pages do not properly clean data before displaying it. An attacker with administrative access to site configurations could use this to inject malicious scripts into the system. This could lead to unauthorized actions being performed in the context of other users' sessions when they encounter these error pages.
Technical details
A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Mattermost Server due to improper neutralization of input during error page generation. The root cause is a failure to escape specific variables that are reflected in the HTML output of error pages. An attacker with high privileges (specifically the ability to edit site configurations) can inject malicious JavaScript into these configuration values. When the server generates an error page using these values, the script executes in the victim's browser. The vulnerability is addressed in versions 10.11.14 and 11.5.2.
Affected products
- Mattermost Mattermost Server 10.11.x <= 10.11.13, 11.5.x <= 11.5.1
Timeline
- 2026-05-18: disclosed
- 2026-05-18: advisory
- 2026-06-01: patched: Advisory updated with patch details