Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/mattermost/mattermost
  4. ›
  5. CVE-2025-12756

CVE-2025-12756: Mattermost fails to validate user permissions when deleting comments in Boards

December 1, 2025 (updated December 2, 2025)

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.

References

  • github.com/advisories/GHSA-p6gj-jc38-x2m7
  • github.com/mattermost/mattermost
  • mattermost.com/security-updates
  • nvd.nist.gov/vuln/detail/CVE-2025-12756

Code Behaviors & Features

Detect and mitigate CVE-2025-12756 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 10.5.0 up to 10.5.12, all versions starting from 10.11.0 up to 10.11.4, all versions starting from 10.12.0 up to 10.12.1, all versions starting from 11.0.0 up to 11.0.2

Solution

Unfortunately, there is no solution available yet.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

go/github.com/mattermost/mattermost/CVE-2025-12756.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 14 Dec 2025 00:19:40 +0000.