Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
Low severity
GitHub Reviewed
Published
May 18, 2026
to the GitHub Advisory Database
•
Updated Jun 1, 2026
Package
Affected versions
< 5.3.2-0.20260325160634-e738016c5920
Patched versions
5.3.2-0.20260325160634-e738016c5920
>= 11.5.0, < 11.5.2
>= 10.11.0, < 10.11.14
< 8.0.0-20260325160634-e738016c5920
11.5.2
10.11.14
8.0.0-20260325160634-e738016c5920
Description
Published by the National Vulnerability Database
May 18, 2026
Published to the GitHub Advisory Database
May 18, 2026
Last updated
Jun 1, 2026
Reviewed
Jun 1, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582
References