CyberRota Analysis
AI-GeneratedThe Mattermost GitLab plugin in versions up to 11.8, 10.20.11, and 11.5.7.0 is vulnerable due to inadequate verification of channel permissions and insufficient validation of API parameters, allowing authenticated attackers to inject unauthorized bot-authored messages with arbitrary URLs into restricted channels. This could lead to potential phishing attacks or the spread of malicious content within the organization. Organizations using affected versions of GitLab should prioritize patching to mitigate these risks.
Original NVD Description
Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to inject bot-authored messages containing arbitrary URLs into channels they do not have access to via the_ {{createIssue}} _and_ {{attachCommentToIssue}} _API endpoints._ Mattermost Advisory ID: MMSA-2026-00673