File Upload Validation Flaw in Mattermost Products by Mattermost
CVE-2025-49222
What is CVE-2025-49222?
Mattermost versions exhibit a vulnerability related to upload type validation during remote cluster upload sessions. This issue allows system administrators to upload non-attachment file types via shared channels. Consequently, these files may be handled in arbitrary filesystem directories, posing a risk of unintended file exposure and system integrity compromise. It's crucial for users and administrators to be aware of this vulnerability and implement necessary measures to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 10.8.0 <= 10.8.3
Mattermost 10.5.0 <= 10.5.8
Mattermost 9.11.0 <= 9.11.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved