CVE-2026-13426
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Jun 26, 2026
Vendor
unknown
Description
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID: MMSA-2025-00532