<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 13:30:38 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0660 — De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0660</link>
      <description>certfr-2026-avi-0660</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0660</guid>
    </item>
    <item>
      <title>EUVD-2026-330636</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330636</link>
      <description>EUVD-2026-330636</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330636</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4339</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4339</link>
      <description>&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.18, 11.6.x &amp;lt;= 11.6.3, 11.5.x &amp;lt;= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.18, 11.6.x &amp;lt;= 11.6.3, 11.5.x &amp;lt;= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4339</guid>
    </item>
    <item>
      <title>GHSA-p3qg-h7r3-79xr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p3qg-h7r3-79xr</link>
      <description>&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.18, 11.6.x &amp;lt;= 11.6.3, 11.5.x &amp;lt;= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.18, 11.6.x &amp;lt;= 11.6.3, 11.5.x &amp;lt;= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p3qg-h7r3-79xr</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1705 — Mattermost Server und Plugins: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1705</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mattermost Server und Plugins ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mattermost Server und Plugins ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1705</guid>
    </item>
  </channel>
</rss>
