Path Traversal Vulnerability in Mattermost Leading to Arbitrary File Writing
CVE-2025-4981
9.9CRITICAL
What is CVE-2025-4981?
Certain versions of Mattermost are affected by a path traversal vulnerability that fails to properly sanitize filenames during file uploads through the archive extractor. Authenticated users can exploit this flaw to upload archives containing path traversal sequences, thus allowing them to write files to arbitrary locations on the filesystem. This could lead to potential remote code execution if the impacted instance is configured to enable file uploads and content extraction, which are default settings. Users should ensure they are aware of this vulnerability and consider applying necessary security measures as outlined in the relevant security updates.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.5
Mattermost 9.11.0 <= 9.11.15
Mattermost 10.8.0