File Upload Validation Flaw in Mattermost Products by Mattermost
CVE-2025-49222
6.8MEDIUM
What is CVE-2025-49222?
Mattermost versions exhibit a vulnerability related to upload type validation during remote cluster upload sessions. This issue allows system administrators to upload non-attachment file types via shared channels. Consequently, these files may be handled in arbitrary filesystem directories, posing a risk of unintended file exposure and system integrity compromise. It's crucial for users and administrators to be aware of this vulnerability and implement necessary measures to mitigate potential risks.
Affected Version(s)
Mattermost 10.8.0 <= 10.8.3
Mattermost 10.5.0 <= 10.5.8
Mattermost 9.11.0 <= 9.11.17