Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate invite tokens after use which allows malicious actors who have intercepted invite tokens to manipulate channel memberships including adding or removing users from private channels via token replay attack.
References
History

Wed, 17 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate invite tokens after use which allows malicious actors who have intercepted invite tokens to manipulate channel memberships including adding or removing users from private channels via token replay attack.
Title Mattermost Remote Cluster Invite Token Replay
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-12-17T19:29:39.872Z

Reserved: 2025-11-17T17:07:12.922Z

Link: CVE-2025-13324

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-17T19:16:01.093

Modified: 2025-12-17T19:16:01.093

Link: CVE-2025-13324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.