
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13352 is a bot identity validation bypass vulnerability in the Mattermost GitHub plugin that allows authenticated attackers to hijack the GitHub reaction feature, tricking users into adding reactions to arbitrary GitHub objects via crafted notification posts. It affects Mattermost versions 10.11.x ≤ 10.11.6 and Mattermost GitHub plugin versions ≤ 2.4.0. The vulnerability was published on December 17, 2025, with patches released the same day. It carries a CVSS v3.1 base score of 3.0 (Low) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-1287 (Improper Validation of Specified Type of Input): the Mattermost GitHub plugin fails to validate the identity of the plugin bot during the reaction forwarding process, meaning it does not confirm that a notification post originates from the legitimate GitHub plugin bot before processing reaction events. An authenticated, low-privilege attacker can craft a malicious notification post that mimics a legitimate GitHub plugin notification, causing the reaction forwarding mechanism to associate user reactions with arbitrary GitHub objects (e.g., issues, pull requests, or comments) chosen by the attacker. Exploitation requires network access, high attack complexity, and user interaction (a victim must react to the crafted post) (GitHub Advisory).
Successful exploitation allows an attacker to manipulate GitHub repository interactions by causing users to unknowingly add reactions to arbitrary GitHub objects, potentially skewing engagement metrics or misleading repository maintainers about community sentiment. The impact is limited to integrity (low), with no confidentiality or availability impact. There is no evidence of lateral movement potential or sensitive data exposure associated with this vulnerability (GitHub Advisory, Mattermost Security).
api.github.com/repos/.../reactions) triggered by user reactions on posts that were not created by the GitHub plugin bot.Update Mattermost server to version 10.11.7 (specifically ≥ 10.11.7-0.20251106103514-3b05384dd014) or 11.1.0 and later, and update the Mattermost GitHub plugin to version ≥ 1.0.1-0.20250829075715-0deffcfc6bee. No configuration-based workaround has been published; upgrading both the server and plugin is the recommended remediation. Additionally, administrators should implement strict channel access controls to limit who can post in channels where the GitHub plugin is active, and monitor for suspicious reaction activity (GitHub Advisory, Mattermost Security).
The vulnerability received limited public attention given its low severity score. It was noted in automated vulnerability tracking feeds including VulnDB, CVEFeed, and CIRCL's vulnerability lookup service shortly after disclosure. No significant researcher commentary, vendor blog posts, or media coverage beyond the standard advisory and aggregator entries has been observed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."