File Path Vulnerability in Mattermost by Mattermost Inc.
CVE-2026-6957
8HIGH
What is CVE-2026-6957?
Mattermost Plugins versions up to 1.1.5 are susceptible to a vulnerability that results from inadequate sanitization of filenames obtained from federated peers. When an administrator from a remote Mattermost server sends a crafted filename via the attachment sync protocol of shared channels, it enables the attacker to manipulate file paths on the target server. This flaw allows an attacker to write files to arbitrary locations within the server's filestore, potentially leading to unauthorized access to sensitive data or other malicious actions.
Affected Version(s)
Mattermost 0 <= 1.1.5
Mattermost .0