CVE-2025-25279Critical· 9.9▾ AbyssalPoC availableMattermost allows reading arbitrary files related to importing boards
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 54.5 · likelihood 4.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
24%
2 GitHub repos (last check)
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.
github.com/mattermost/mattermost/server/v8 < 8.0.0-20250122165010-4ed702ccff4egithub.com/mattermost/mattermost/server/v8 >= 9.11.0-rc1, < 9.11.8github.com/mattermost/mattermost/server/v8 >= 10.2.0-rc1, < 10.2.3github.com/mattermost/mattermost/server/v8 >= 10.3.0-rc1, < 10.3.3github.com/mattermost/mattermost/server/v8 >= 10.4.0-rc1, < 10.4.2Upgrade to a patched release:
github.com/mattermost/mattermost/server/v8 8.0.0-20250122165010-4ed702ccff4egithub.com/mattermost/mattermost/server/v8 9.11.8github.com/mattermost/mattermost/server/v8 10.2.3github.com/mattermost/mattermost/server/v8 10.3.3github.com/mattermost/mattermost/server/v8 10.4.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names
CVE-2025-2475Medium· 5.4Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm