ZeroHour

CVE-2025-25279

mass

Unauthenticated Arbitrary File Read via Board Import in Mattermost

CVSS 3.1
7.5 high
EPSS
24%p98
Published
()
Modified
AI analysis

Mattermost Server fails to properly validate board blocks when importing boards through its Boards feature, a path traversal flaw (CWE-22). An attacker submits a specially crafted board import archive and then exports it, causing the traversal to embed files from elsewhere on the server's filesystem into the exported archive. This yields an arbitrary file read, which can expose sensitive server contents such as configuration files containing database credentials and other secrets. Instances running affected 10.4.x, 10.3.x, 10.2.x, or 9.11.x releases with board import available to users are at risk; the CVSS vector indicates no special privileges or user interaction are required. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but the EPSS score of 24.2% (98th percentile) signals an elevated likelihood of exploitation attempts within 30 days.

What to do: Upgrade Mattermost Server to a release newer than the affected ceiling in your line — above 10.4.1, 10.3.2, 10.2.2, or 9.11.7 as applicable (i.e., the current patched release of each supported series). Until patched, limit board import to trusted users or disable the Boards feature/plugin if it is not used. Given the arbitrary file read, review whether sensitive files such as the Mattermost config (which holds database and SMTP credentials) could have been exposed, and watch for import activity in server logs.

Affected
Mattermost Server10.4.x <= 10.4.1
Mattermost Server10.3.x <= 10.3.2
Mattermost Server10.2.x <= 10.2.2
Mattermost Server9.11.x <= 9.11.7
Estimated exposure
mass≈ millions of users across hundreds of thousands of self-hosted Mattermost instances (order-of-magnitude estimate) — Mattermost is one of the most widely deployed open-source team-collaboration platforms with a very large self-hosted install base (reflected in hundreds of millions of pulls of its official Docker image), and the Boards feature is bundled…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.