Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Thu, 21 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost |
|
Vendors & Products |
Mattermost
Mattermost mattermost |
Thu, 21 Aug 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions. | |
Title | Import Path Traversal Enables Unauthorized Unsigned Plugin Installation | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published: 2025-08-21T07:11:43.241Z
Updated: 2025-08-21T13:50:42.949Z
Reserved: 2025-07-22T07:46:53.193Z
Link: CVE-2025-36530

No data.

Status : Received
Published: 2025-08-21T07:15:29.550
Modified: 2025-08-21T07:15:29.550
Link: CVE-2025-36530

No data.