6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Description
Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.
Basic Information
ID
CVE-2025-6233
Source
Mattermost
Published
Jul 18, 2025 at 09:09
Modified
Jul 18, 2025 at 12:30
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
10.8.0
Affected Versions
Mattermost Mattermost 10.8.0
Mattermost Mattermost 10.7.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 9.11.0
Mattermost Mattermost 10.7.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 9.11.0