Back to overview

CVE-2025-4981

CRITICAL
9.9
CVSS 3.1
Description
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.

Metadata

CVE ID
CVE-2025-4981
State
PUBLISHED
Assigner
Mattermost
Reserved
2025-05-20 06:57 UTC
Published
2025-06-20 10:27 UTC
Last updated
2025-06-20 13:10 UTC
Primary CWE
CWE-427
CWE-427: Uncontrolled Search Path Element
Vendor / Product
Mattermost / Mattermost
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Mattermost Mattermost 10.5.0 ≤ 10.5.5, 9.11.0 ≤ 9.11.15, 10.8.0 ≤ 10.8.0, 10.7.0 ≤ 10.7.2 …
Weakness (CWE)
CWESourceDescription
CWE-427 cna CWE-427: Uncontrolled Search Path Element
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview