cve/2025/CVE-2025-41423.md
2025-09-29 21:09:30 +02:00

1.1 KiB

CVE-2025-41423

Description

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.

POC

Reference

Github

No PoCs found on GitHub currently.