Description
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during authentication failures. Mattermost Advisory ID: MMSA-2026-00609
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Mattermost / Mattermost0 – 10.18.11
- Mattermost / Mattermost0 – 11.3.6
- Mattermost / Mattermost0 – 11.6.5
- Mattermost / Mattermost11.7.0 – 11.7.0
- Mattermost / Mattermost10.11.19 – 10.11.19
- Mattermost / Mattermost11.6.4 – 11.6.4
- Mattermost / Mattermost11.5.7 – 11.5.7