StackRadar

CVE-2025-13352

Unscored

Advisory

Published 22 Dec 2025In the index since 6 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
8
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
None
affected packages

Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost

Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/mattermost/mattermost-server/v5golangv5.3.2-0.20210503144558-5c16de58a020, v5.3.2-0.20210524045451-a4f7df6f6e3c, v5.32.1, v5.34.2+1 moreno fix listed5
github.com/mattermost/mattermost/server/v8golangv0.0.0-20231206131006-d6edda074a4b, v0.0.0-20250821100404-2a35a97a1877+dirtyno fix listed2
github.com/mattermost/mattermost-server/v6golangv6.7.2no fix listed1
OSV records
GO-2025-4247
Also known as
GHSA-jf5h-xfw4-p8gp

Charts affected

8 by stars
ChartLatestAffected imagesRadar Score
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b
no fix listed

Open the chart page →

8,722
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210524045451-a4f7df6f6e3c
no fix listed

Open the chart page →

3,631
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
github.com/mattermost/mattermost-server/v5@v5.39.3
github.com/mattermost/mattermost-server/v6@v6.7.2
no fix listed
no fix listed

Open the chart page →

5,074
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
github.com/mattermost/mattermost-server/v5@v5.34.2
no fix listed

Open the chart page →

4,014
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210503144558-5c16de58a020
no fix listed

Open the chart page →

4,067
mattermost-team-editionmattermost-team-edition6.6.831 of 4See more

mattermost-team-edition mattermost-team-edition 6.6.83

1 of the 4 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
github.com/mattermost/mattermost/server/v8@v0.0.0-20250821100404-2a35a97a1877+dirty
no fix listed

Open the chart page →

4,089
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
github.com/mattermost/mattermost/server/v8@v0.0.0-20250821100404-2a35a97a1877+dirty
no fix listed

Open the chart page →

4,089
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-13352.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
github.com/mattermost/mattermost-server/v5@v5.32.1
no fix listed

Open the chart page →

4,158

Container images carrying it

7 by charts deploying them

A fixed version is listed for 0 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
github.com/mattermost/mattermost/server/v8@v0.0.0-20250821100404-2a35a97a1877+dirty
no fix listed
2
mattermost/focalboard:0.9.031078df7a3c8
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210524045451-a4f7df6f6e3c
no fix listed
1
mattermost/focalboard:0.6.7f2f987dada52
github.com/mattermost/mattermost-server/v5@v5.34.2
no fix listed
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210503144558-5c16de58a020
no fix listed
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b
no fix listed
1
phntom/mindav:0.1.7-kix35695f546abbb
github.com/mattermost/mattermost-server/v5@v5.32.1
no fix listed
1
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
github.com/mattermost/mattermost-server/v5@v5.39.3
github.com/mattermost/mattermost-server/v6@v6.7.2
no fix listed
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.