Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4981


Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.


Published

2025-06-20T11:15:20.993

Last Modified

2025-07-08T17:59:42.473

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 9.11.16 Yes
Application mattermost mattermost_server < 10.5.6 Yes
Application mattermost mattermost_server < 10.6.6 Yes
Application mattermost mattermost_server < 10.7.3 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes

References