CVE-2025-64641 is a medium-severity vulnerability affecting Mattermost versions 11.1.0 and earlier, 11.0.5 and earlier, 10.12.3 and earlier, and 10.11.7 and earlier. It allows a malicious Mattermost user to exfiltrate Jira tickets by crafting posts that trick victim users into interacting with a /share-issue-publicly action not originating from the legitimate Jira plugin. The vulnerability has a CVSS score of 4.1 (MEDIUM) due to its network-based attack vector, low complexity, and requirement for user interaction, leading to a potential low confidentiality impact. There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.11.0, <= 10.11.7CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.12.0, <= 10.12.3CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.0.0, <= 11.0.5CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.1.0, <= 11.1.0CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.11.0, < 10.11.8CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.