Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.
References
History

Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 21 Aug 2025 07:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.
Title Import Path Traversal Enables Unauthorized Unsigned Plugin Installation
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-08-21T07:11:43.241Z

Updated: 2025-08-21T13:50:42.949Z

Reserved: 2025-07-22T07:46:53.193Z

Link: CVE-2025-36530

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-08-21T07:15:29.550

Modified: 2025-08-21T07:15:29.550

Link: CVE-2025-36530

cve-icon Redhat

No data.