Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious file placement outside intended directories.
References
History

Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 21 Aug 2025 08:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious file placement outside intended directories.
Title Path Traversal in Template Upload Allows Uploading Files Outside Target Directory
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-08-21T07:51:37.130Z

Updated: 2025-08-21T07:51:37.130Z

Reserved: 2025-07-22T08:03:06.489Z

Link: CVE-2025-8023

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-08-21T08:15:30.720

Modified: 2025-08-21T08:15:30.720

Link: CVE-2025-8023

cve-icon Redhat

No data.