{"schema_version":1,"title":"Mattermost GitHub Plugin for Mattermost vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 3 vulnerabilities in Mattermost GitHub Plugin for Mattermost: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-28735, was published on 22 May 2026.","url":"https://junglewise.ai/threats/technologies/github-plugin","json_url":"https://junglewise.ai/threats/technologies/github-plugin.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-plugin","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":3,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":3},"latest":[{"cve":"CVE-2026-28735","cvss":5.4,"epss":0.0023,"slug":"cve-2026-28735-mattermost-incorrect-oauth-token-scope-validation-in-github","title":"Mattermost incorrect OAuth token scope validation in GitHub integration","severity":"medium","exploited":false,"published_at":"2026-05-22T17:16:46.26+00:00","url":"https://junglewise.ai/threats/cve-2026-28735-mattermost-incorrect-oauth-token-scope-validation-in-github"},{"cve":"CVE-2026-5308","cvss":7.5,"epss":0.0045,"slug":"cve-2026-5308-mattermost-denial-of-service-in-plugin-http-endpoints","title":"Mattermost denial of service in plugin HTTP endpoints","severity":"high","exploited":false,"published_at":"2026-05-22T11:16:23.047+00:00","url":"https://junglewise.ai/threats/cve-2026-5308-mattermost-denial-of-service-in-plugin-http-endpoints"},{"cve":"CVE-2026-4646","cvss":4.3,"epss":0.0043,"slug":"cve-2026-4646-mattermost-server-denial-of-service-in-pr-details-endpoint","title":"Mattermost Server denial of service in PR details endpoint","severity":"medium","exploited":false,"published_at":"2026-05-22T11:16:22.863+00:00","url":"https://junglewise.ai/threats/cve-2026-4646-mattermost-server-denial-of-service-in-pr-details-endpoint"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Mattermost Server","slug":"server-public","vulnerabilities":69,"url":"https://junglewise.ai/threats/technologies/server-public"},{"name":"Mattermost Desktop App","slug":"desktop-app","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/desktop-app"},{"name":"Mattermost","slug":"mattermost","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/mattermost"},{"name":"Mattermost Plugins","slug":"mattermost-plugins","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/mattermost-plugins"}],"technology":{"hub":true,"name":"Mattermost GitHub Plugin for Mattermost","slug":"github-plugin","vendor":{"name":"Mattermost","slug":"mattermost","url":"https://junglewise.ai/threats/vendors/mattermost"},"aliases":["github-plugin-for-mattermost"],"category":"library","homepage":"https://github.com/mattermost/mattermost-plugin-github","repo_url":"https://github.com/mattermost/mattermost-plugin-github","description":"The GitHub plugin for Mattermost allows users to receive notifications and manage GitHub repositories directly from the Mattermost interface.","url":"https://junglewise.ai/threats/technologies/github-plugin"},"most_severe":[{"cve":"CVE-2026-5308","cvss":7.5,"epss":0.0045,"slug":"cve-2026-5308-mattermost-denial-of-service-in-plugin-http-endpoints","title":"Mattermost denial of service in plugin HTTP endpoints","severity":"high","exploited":false,"published_at":"2026-05-22T11:16:23.047+00:00","url":"https://junglewise.ai/threats/cve-2026-5308-mattermost-denial-of-service-in-plugin-http-endpoints"},{"cve":"CVE-2026-28735","cvss":5.4,"epss":0.0023,"slug":"cve-2026-28735-mattermost-incorrect-oauth-token-scope-validation-in-github","title":"Mattermost incorrect OAuth token scope validation in GitHub integration","severity":"medium","exploited":false,"published_at":"2026-05-22T17:16:46.26+00:00","url":"https://junglewise.ai/threats/cve-2026-28735-mattermost-incorrect-oauth-token-scope-validation-in-github"},{"cve":"CVE-2026-4646","cvss":4.3,"epss":0.0043,"slug":"cve-2026-4646-mattermost-server-denial-of-service-in-pr-details-endpoint","title":"Mattermost Server denial of service in PR details endpoint","severity":"medium","exploited":false,"published_at":"2026-05-22T11:16:22.863+00:00","url":"https://junglewise.ai/threats/cve-2026-4646-mattermost-server-denial-of-service-in-pr-details-endpoint"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}