CVE 6.8 MEDIUM

Import Path Traversal Enables Unauthorized Unsigned Plugin Installation_CVE-2025-36530

6.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Description

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.

Basic Information

ID CVE-2025-36530
Source Mattermost
Published Aug 21, 2025 at 07:11

Affected Product

Vendor Mattermost
Product Mattermost
Version 10.9.0
Affected Versions Mattermost Mattermost 10.9.0
Mattermost Mattermost 10.8.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 9.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.