CVE-2025-64641
vulnerability analysis and mitigation

Overview

CVE-2025-64641 is an incorrect authorization vulnerability in Mattermost Server that allows a low-privileged user to exfiltrate Jira ticket data by crafting malicious posts that invoke the /share-issue-publicly endpoint without proper plugin origin verification. It affects Mattermost Server versions 10.11.0–10.11.7, 10.12.0–10.12.3, 11.0.0–11.0.5, and 11.1.0. The vulnerability was published on December 24, 2025, and carries a CVSS v3.1 base score of 4.1 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): Mattermost fails to verify that post actions invoking the /share-issue-publicly endpoint were originated by the legitimate Jira plugin, allowing any authenticated user to craft a post that triggers this action (GitHub Advisory). An attacker with low-privileged Mattermost access can create a specially crafted post containing a post action that calls /share-issue-publicly; when a victim user interacts with the post (e.g., clicks a button), the action executes in the context of the Jira plugin integration, leaking Jira issue details to the attacker. Exploitation requires network access, low privileges, and victim user interaction, with a changed scope indicating the impact crosses the Mattermost security boundary into Jira data (GitHub Advisory).

Impact

Successful exploitation allows a malicious Mattermost user to exfiltrate sensitive Jira ticket contents — including potentially confidential project data, issue descriptions, and metadata — when victim users interact with attacker-crafted posts. The impact is limited to confidentiality (no integrity or availability impact), but the changed scope means data from the Jira integration is exposed beyond the attacker's normal access boundary. There is no evidence of lateral movement capability or broader system compromise from this vulnerability alone (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Gain low-privileged access: Obtain a valid Mattermost user account on an instance running an affected version (10.11.0–10.11.7, 10.12.0–10.12.3, 11.0.0–11.0.5, or 11.1.0) with the Jira plugin enabled.
  2. Craft a malicious post: Create a Mattermost post containing a post action (interactive button or menu) that invokes the /share-issue-publicly endpoint, referencing a target Jira issue ID, without the action being legitimately generated by the Jira plugin.
  3. Deliver the post to victims: Share the crafted post in a channel or direct message where target users (who have Jira access) are likely to interact with it.
  4. Trigger victim interaction: When a victim user clicks the malicious action button in the post, the Mattermost server processes the /share-issue-publicly action without verifying its origin, causing Jira ticket details to be shared or returned.
  5. Collect exfiltrated data: The attacker receives or observes the Jira ticket contents exposed through the improperly authorized action (GitHub Advisory).

Indicators of compromise

  • Logs: Mattermost server logs showing /share-issue-publicly post action invocations originating from posts not created by the Jira plugin integration account; unexpected or repeated calls to this endpoint from non-plugin user IDs.
  • Mattermost Audit Logs: Post action events triggered by user-created posts (rather than plugin-generated posts) referencing Jira issue IDs, especially from accounts that do not normally interact with Jira.
  • Network: Unusual outbound requests from the Mattermost server to Jira APIs triggered by post action events outside of normal plugin activity patterns.

Mitigation and workarounds

Mattermost has released patched versions that enforce proper origin verification for /share-issue-publicly post actions. Administrators should upgrade to one of the following fixed versions: 10.11.8, 10.12.4, 11.0.6, or 11.1.1 (GitHub Advisory, Mattermost Security Updates). As a temporary workaround if immediate patching is not possible, disabling the Jira plugin integration will prevent exploitation of this specific attack vector. Additionally, restricting channel membership and monitoring post action logs for anomalous /share-issue-publicly invocations can reduce risk.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management