go package reportIs github.com/mattermost/mattermost-plugin-github safe ? 3 known vulnerabilities, worst severity HIGH.
// reach 0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
// ai model usage Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
epss chance of exploitation in 30 days, 36th percentile of all CVEs
xyz score CyberXYZ composite out of 10
fig. 01 — GHSA-jmvr-r5hm-fxfr, the advisory selected below
// 3 advisories GHSA-jmvr-r5hm-fxfr Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTTP requests.. Mattermost Advisory ID: MMSA-2026-00646 HIGH GHSA-rmvv-8v8w-rf7x Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTTP request to the PR details endpoint. Mattermost Advisory ID: MMSA-2026-00638 MODE GHSA-r5vf-grcx-5vqp Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL. Mattermost Advisory ID: MMSA-2026-00628 MODE Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTTP requests.. Mattermost Advisory ID: MMSA-2026-00646
// cvss v3.1 vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High // fixed in 1.0.1-0.20260410143745-9b41b1fd43c4
go get github.com/mattermost/mattermost-plugin-github@v1.0.1-0.20260410143745-9b41b1fd43c4 upgrade past every affected range above
// at a glance Affected < 1.0.1-0.20260410143745-9b41b1fd43c4 Fixed in 1.0.1-0.20260410143745-9b41b1fd43c4 Weakness CWE-400 Uncontrolled resource consumption Published 2026-05-26updated 2026-06-29 Sources github Checked 2026-09-26 at 00:59 UTC. The most recent advisory here was published 2026-05-26. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us — we respond within 2 business days. Report an issue with this page