Vulnerability Description
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost Server | >= 10.5.0, < 10.5.13 |
Related Weaknesses (CWE)
References
- https://mattermost.com/security-updatesVendor Advisory
FAQ
What is CVE-2025-13870?
CVE-2025-13870 is a vulnerability with a CVSS score of 3.1 (LOW). Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to ac...
How severe is CVE-2025-13870?
CVE-2025-13870 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13870?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost Server.