Path Traversal Vulnerability in Mattermost Plugin Import Functionality
CVE-2025-36530
6.8MEDIUM
What is CVE-2025-36530?
Mattermost versions 10.9.x through 10.9.1, 10.8.x through 10.8.3, 10.5.x through 10.5.8, and 9.11.x through 9.11.17 contain a vulnerability where file paths are not properly validated during plugin import operations. This flaw enables restricted admin users to exploit the import functionality, allowing them to install unauthorized custom plugins. By leveraging path traversal techniques, attackers can circumvent plugin signature enforcement and marketplace restrictions, potentially compromising the integrity of the Mattermost environment.
Affected Version(s)
Mattermost 10.9.0 <= 10.9.1
Mattermost 10.8.0 <= 10.8.3
Mattermost 10.5.0 <= 10.5.8