4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
Basic Information
ID
CVE-2025-6465
Source
Mattermost
Published
Aug 21, 2025 at 17:01
Modified
Aug 21, 2025 at 17:30
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
10.8.0
Affected Versions
Mattermost Mattermost 10.8.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 10.10.0
Mattermost Mattermost 10.9.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 10.10.0
Mattermost Mattermost 10.9.0