๐Ÿ” CVE Alert

CVE-2026-4339

MEDIUM 6.5

SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635

CWE CWE-918
Vendor mattermost
Product mattermost
Published Jun 26, 2026
Last Updated Jun 26, 2026
Stay Ahead of the Next One

Get instant alerts for mattermost mattermost

Be the first to know when new medium vulnerabilities affecting mattermost mattermost are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Mattermost / Mattermost
10.11.0 โ‰ค 10.11.18 11.6.0 โ‰ค 11.6.3 11.5.0 โ‰ค 11.5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mattermost.com: https://mattermost.com/security-updates

Credits

s00me00ne