Path Traversal Vulnerability in Mattermost Plugin Import Functionality
CVE-2025-36530
What is CVE-2025-36530?
Mattermost versions 10.9.x through 10.9.1, 10.8.x through 10.8.3, 10.5.x through 10.5.8, and 9.11.x through 9.11.17 contain a vulnerability where file paths are not properly validated during plugin import operations. This flaw enables restricted admin users to exploit the import functionality, allowing them to install unauthorized custom plugins. By leveraging path traversal techniques, attackers can circumvent plugin signature enforcement and marketplace restrictions, potentially compromising the integrity of the Mattermost environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 10.9.0 <= 10.9.1
Mattermost 10.8.0 <= 10.8.3
Mattermost 10.5.0 <= 10.5.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved