CVE-2025-41423
CVSS 3.1 Score 3.1 of 10 (low)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 863
Summary
CVE-2025-41423 is a vulnerability affecting Mattermost versions 10.4.x up to 10.4.2, 10.5.x up to 10.5.0, and 9.11.x up to 9.11.10. The issue lies in the failure to adequately validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread. Consequently, any user or attacker can delete posts containing actions created by the Playbooks bot, even if they lack channel access or the necessary permissions. This vulnerability could potentially lead to unintended data loss or disruption to team communications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost