Junglewise Threat Intelligence

CVE-2026-6333: Mattermost Server SSRF via Host header in slash commands

CVE-2026-6333 · Severity: low · CVSS 3.5 · Published 2026-05-18

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost, a collaboration and messaging platform, is affected by a vulnerability in how it handles custom slash commands. An authenticated user could manipulate network headers to redirect command responses to a server they control. This could lead to the redirection of internal communications or automated responses to unauthorized external destinations.

Technical details

Mattermost versions 11.5.x (<= 11.5.1) and 10.11.x (<= 10.11.13) are vulnerable to a Server-Side Request Forgery (SSRF) variant. The application fails to validate the 'Host' header when generating response URLs for custom slash commands. An authenticated attacker can provide a spoofed Host header in their request, causing the server to construct and send slash command responses to an attacker-controlled destination. The fix involves requiring and validating the 'SiteURL' for external-facing slash commands rather than relying on user-supplied headers.

Affected products

  • Mattermost Mattermost Server >= 11.5.0, < 11.5.2; >= 10.11.0, < 10.11.14; < 8.0.0-20260325160634-e738016c5920

Timeline

  • 2026-03-25: patched: Fix committed to repository
  • 2026-05-18: disclosed: Initial advisory and CVE published

References

Related threats