Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-gq3r-5833-5532: Mattermost Fails to Validate File Paths

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.

ghsa
#git#perl#auth
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-36530

Mattermost Fails to Validate File Paths

Moderate severity GitHub Reviewed Published Aug 21, 2025 to the GitHub Advisory Database • Updated Aug 21, 2025

Package

gomod github.com/mattermost/mattermost-server (Go)

Affected versions

>= 10.9.0, <= 10.9.1

>= 10.8.0, <= 10.8.3

>= 10.5.0, <= 10.5.8

>= 9.11.0, <= 9.11.17

Patched versions

10.9.2

10.8.4

10.5.9

9.11.18

gomod github.com/mattermost/mattermost/server/v8 (Go)

< 8.0.0-20250619095651-9dd0b3943e55

8.0.0-20250619095651-9dd0b3943e55

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-36530
  • https://mattermost.com/security-updates

Published to the GitHub Advisory Database

Aug 21, 2025

Last updated

Aug 21, 2025

ghsa: Latest News

GHSA-g5qg-72qw-gw5v: Next.js Affected by Cache Key Confusion for Image Optimization API Routes