Path Traversal Vulnerability in Mattermost Plugin Import Functionality
CVE-2025-36530

6.8MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
21 August 2025

What is CVE-2025-36530?

Mattermost versions 10.9.x through 10.9.1, 10.8.x through 10.8.3, 10.5.x through 10.5.8, and 9.11.x through 9.11.17 contain a vulnerability where file paths are not properly validated during plugin import operations. This flaw enables restricted admin users to exploit the import functionality, allowing them to install unauthorized custom plugins. By leveraging path traversal techniques, attackers can circumvent plugin signature enforcement and marketplace restrictions, potentially compromising the integrity of the Mattermost environment.

Affected Version(s)

Mattermost 10.9.0 <= 10.9.1

Mattermost 10.8.0 <= 10.8.3

Mattermost 10.5.0 <= 10.5.8

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dawid Kulikowski (daw10)
.