CVE Vulnerabilities

CVE-2025-6227

Insufficiently Protected Credentials

Published: Jul 18, 2025 | Modified: Oct 14, 2025
CVSS 3.x
3.1
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Mattermost_serverMattermost9.11.0 (including)9.11.17 (excluding)
Mattermost_serverMattermost10.5.0 (including)10.5.8 (excluding)

Potential Mitigations

References