CVE-2025-55074CWE-1426

Channel member objects leak read status

Low · published November 18, 2025

CVSS v3.1
3.0
EPSS
0%
Percentile
6.5
In the wild
Unconfirmed
What it is

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

The record
Technical detail
CVSS v3.1
3.0 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00169 · 6.5th percentile
Weakness
CWE-1426 · Improper Validation of Generative AI Output
Published
2025-11-18T15:23Z
EPSS history
Timeline
  • 18 NOV 15:23Z
    Channel member objects leak read status
    cvelistv5