PT-2025-38614 · Mattermost · Mattermost
Daw10
·
Published
2025-09-19
·
Updated
2025-09-26
·
CVE-2025-9079
8.0
High
Base vector | Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 10.8.x through 10.8.3
Mattermost versions 10.5.x through 10.5.8
Mattermost versions 9.11.x through 9.11.17
Mattermost versions 10.10.x through 10.10.1
Mattermost versions 10.9.x through 10.9.3
Mattermost versions prior to 10.10.2
**Description**
The Mattermost server fails to properly validate the import directory path configuration. This allows administrator users to potentially execute arbitrary code by uploading a malicious plugin to the prepackaged plugins directory. The issue is a path traversal, enabling unauthorized access and code execution.
**Recommendations**
Mattermost versions 10.8.x through 10.8.3 should be updated to a version later than 10.8.3.
Mattermost versions 10.5.x through 10.5.8 should be updated to a version later than 10.5.8.
Mattermost versions 9.11.x through 9.11.17 should be updated to a version later than 9.11.17.
Mattermost versions 10.10.x through 10.10.1 should be updated to a version later than 10.10.1.
Mattermost versions 10.9.x through 10.9.3 should be updated to a version later than 10.9.3.
Mattermost versions prior to 10.10.2 should be updated to version 10.10.2 or later.
Fix
RCE
Path traversal
Weakness Enumeration
Related Identifiers
Affected Products
References · 20
- https://osv.dev/vulnerability/GHSA-qx3f-6vq3-8j8m · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9079 · Security Note
- https://mattermost.com/security-updates · Vendor Advisory
- https://osv.dev/vulnerability/GO-2025-3977 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2025-9079 · Vendor Advisory
- https://github.com/mattermost/mattermost/commit/96665b9b98a17534fcd515982a2eb26950581e41⭐ 33848 🔗 7999 · Note
- https://github.com/mattermost/mattermost/commit/b38e2eccda182212a8032539658723c7d87e0b7e⭐ 33848 🔗 7999 · Note
- https://github.com/mattermost/mattermost/commit/047a2c64071749367fe02d2162f6103a3d31a883⭐ 33848 🔗 7999 · Note
- https://github.com/mattermost/mattermost/commit/439464883aa16a329c23cd6274c4cca7e88e238f⭐ 33848 🔗 7999 · Note
- https://github.com/mattermost/mattermost/commit/a8fa77f107efe83f09a779f8e67cbecf236b0032⭐ 33848 🔗 7999 · Note
- https://github.com/mattermost/mattermost/commit/4ff68eea0a3f3777032d31a1a82f4b1fb492a1ac⭐ 33848 🔗 7999 · Note
- https://github.com/mattermost/mattermost⭐ 33664 🔗 7980 · Note
- https://t.me/brutsecurity/2262 · Telegram Post
- https://twitter.com/CVEnew/status/1969291929805373678 · Twitter Post
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9079 · Note