← All credits
BhaRat (hackit_bharat)
14 vulnerability records and advisories credit this contributor.
CVE-2025-41436
Unauthorized access to archived channel content via threads interface
CVE-2025-3227
Unauthorized channel member management through playbook runs
CVE-2024-8071
System Role with edit access to permissions can elevate themselves to system admin
CVE-2024-5272
Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated"
CVE-2024-4195
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
CVE-2024-47145
Unauthorized access on archived channels via file links
CVE-2024-43780
Unauthorized channel file upload
CVE-2024-42497
Insufficient permissions checks on teams
CVE-2024-34152
Playbook Run Metadata leak to Guest
CVE-2024-32045
Playbook run link to private channel grants channel access