
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64641 is an incorrect authorization vulnerability in Mattermost Server that allows a low-privileged user to exfiltrate Jira ticket data by crafting malicious posts that invoke the /share-issue-publicly endpoint without proper plugin origin verification. It affects Mattermost Server versions 10.11.0–10.11.7, 10.12.0–10.12.3, 11.0.0–11.0.5, and 11.1.0. The vulnerability was published on December 24, 2025, and carries a CVSS v3.1 base score of 4.1 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization): Mattermost fails to verify that post actions invoking the /share-issue-publicly endpoint were originated by the legitimate Jira plugin, allowing any authenticated user to craft a post that triggers this action (GitHub Advisory). An attacker with low-privileged Mattermost access can create a specially crafted post containing a post action that calls /share-issue-publicly; when a victim user interacts with the post (e.g., clicks a button), the action executes in the context of the Jira plugin integration, leaking Jira issue details to the attacker. Exploitation requires network access, low privileges, and victim user interaction, with a changed scope indicating the impact crosses the Mattermost security boundary into Jira data (GitHub Advisory).
Successful exploitation allows a malicious Mattermost user to exfiltrate sensitive Jira ticket contents — including potentially confidential project data, issue descriptions, and metadata — when victim users interact with attacker-crafted posts. The impact is limited to confidentiality (no integrity or availability impact), but the changed scope means data from the Jira integration is exposed beyond the attacker's normal access boundary. There is no evidence of lateral movement capability or broader system compromise from this vulnerability alone (GitHub Advisory, Red Hat CVE).
/share-issue-publicly endpoint, referencing a target Jira issue ID, without the action being legitimately generated by the Jira plugin./share-issue-publicly action without verifying its origin, causing Jira ticket details to be shared or returned./share-issue-publicly post action invocations originating from posts not created by the Jira plugin integration account; unexpected or repeated calls to this endpoint from non-plugin user IDs.Mattermost has released patched versions that enforce proper origin verification for /share-issue-publicly post actions. Administrators should upgrade to one of the following fixed versions: 10.11.8, 10.12.4, 11.0.6, or 11.1.1 (GitHub Advisory, Mattermost Security Updates). As a temporary workaround if immediate patching is not possible, disabling the Jira plugin integration will prevent exploitation of this specific attack vector. Additionally, restricting channel membership and monitoring post action logs for anomalous /share-issue-publicly invocations can reduce risk.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."