Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-wvw2-3jh4-4c39: Mattermost Path Traversal vulnerability

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.

ghsa
#vulnerability#js#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-6233

Mattermost Path Traversal vulnerability

Moderate severity GitHub Reviewed Published Jul 18, 2025 to the GitHub Advisory Database • Updated Jul 21, 2025

Package

gomod github.com/mattermost/mattermost-server (Go)

Affected versions

>= 10.8.0, < 10.8.2

>= 10.7.0, < 10.7.4

>= 10.5.0, < 10.5.8

>= 9.11.0, < 9.11.17

Patched versions

10.8.2

10.7.4

10.5.8

9.11.17

gomod github.com/mattermost/mattermost/server/v8 (Go)

< 8.0.0-20250529054450-d38c27f96fcf

8.0.0-20250529054450-d38c27f96fcf

Description

Published to the GitHub Advisory Database

Jul 18, 2025

Last updated

Jul 21, 2025

ghsa: Latest News

GHSA-vxq6-8cwm-wj99: LibreNMS allows stored XSS in Alert Template name field