File Upload Validation Flaw in Mattermost Products by Mattermost
CVE-2025-49222

6.8MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
21 August 2025

What is CVE-2025-49222?

Mattermost versions exhibit a vulnerability related to upload type validation during remote cluster upload sessions. This issue allows system administrators to upload non-attachment file types via shared channels. Consequently, these files may be handled in arbitrary filesystem directories, posing a risk of unintended file exposure and system integrity compromise. It's crucial for users and administrators to be aware of this vulnerability and implement necessary measures to mitigate potential risks.

Affected Version(s)

Mattermost 10.8.0 <= 10.8.3

Mattermost 10.5.0 <= 10.5.8

Mattermost 9.11.0 <= 9.11.17

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daw10
.