Vulnerability  ·  2026-06-27

Mattermost Agents MCP Plugin — SSRF via Unvalidated Attachment URLs Allows Internal Network Access

VulnerabilityMedium impactGlobalCVE-2026-4339
Mattermost versions across three release branches fail to validate attachment URLs against internal or private IP ranges in the Agents plugin MCP server component. An authenticated attacker with MCP server access in stdio mode can supply internal network URLs as attachment targets, triggering server-side requests to internal infrastructure (CVSS 6.5).
Mattermost's Agents plugin is specifically designed to integrate AI agents into team communication workflows. SSRF in an MCP server context means an attacker can use the AI agent infrastructure as a pivot to reach internal services, database APIs, AI model endpoints, and cloud metadata services that should not be externally accessible.
The Mattermost Agents plugin MCP server fails to validate attachment URLs against internal or private IP ranges. An attacker with access to the MCP server in stdio mode can supply crafted attachment URLs pointing to internal network addresses, causing the Mattermost server to make SSRF requests to internal services on behalf of the attacker.
Mattermost 10.11.x ≤ 10.11.18, 11.5.x ≤ 11.5.6, 11.6.x ≤ 11.6.3
Update Mattermost to 10.11.19+, 11.5.7+, or 11.6.4+. See: https://mattermost.com/security-updates
Sources
NVD CVE-2026-4339Mattermost Security Updates
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →