Mattermost doesn't restrict domains LLM can request to contact upstream
Low severity
GitHub Reviewed
Published
Apr 16, 2025
to the GitHub Advisory Database
•
Updated Apr 23, 2025
Package
Affected versions
>= 10.5.0, < 10.5.1
>= 10.4.0, < 10.4.3
>= 9.11.0, < 9.11.10
< 8.0.0-20250218121836-2b5275d87136
Patched versions
10.5.1
10.4.3
9.11.10
8.0.0-20250218121836-2b5275d87136
Description
Published by the National Vulnerability Database
Apr 16, 2025
Published to the GitHub Advisory Database
Apr 16, 2025
Reviewed
Apr 16, 2025
Last updated
Apr 23, 2025
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.
References