Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server
02 / AFFECTED SOFTWARE
Affected packages
76 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server
Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6233.json
- https://mattermost.com/security-updates
- https://nvd.nist.gov/vuln/detail/CVE-2025-6233
- https://github.com/advisories/GHSA-wvw2-3jh4-4c39
- https://github.com/mattermost/mattermost/commit/d38c27f96fcf754c36f231d1f2e9dbd48ad40bab
- https://github.com/mattermost/mattermost