CVE-2025-25279
massUnauthenticated Arbitrary File Read via Board Import in Mattermost
Mattermost Server fails to properly validate board blocks when importing boards through its Boards feature, a path traversal flaw (CWE-22). An attacker submits a specially crafted board import archive and then exports it, causing the traversal to embed files from elsewhere on the server's filesystem into the exported archive. This yields an arbitrary file read, which can expose sensitive server contents such as configuration files containing database credentials and other secrets. Instances running affected 10.4.x, 10.3.x, 10.2.x, or 9.11.x releases with board import available to users are at risk; the CVSS vector indicates no special privileges or user interaction are required. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but the EPSS score of 24.2% (98th percentile) signals an elevated likelihood of exploitation attempts within 30 days.
What to do: Upgrade Mattermost Server to a release newer than the affected ceiling in your line — above 10.4.1, 10.3.2, 10.2.2, or 9.11.7 as applicable (i.e., the current patched release of each supported series). Until patched, limit board import to trusted users or disable the Boards feature/plugin if it is not used. Given the arbitrary file read, review whether sensitive files such as the Mattermost config (which holds database and SMTP credentials) could have been exposed, and watch for import activity in server logs.
| Mattermost Server | 10.4.x <= 10.4.1 |
| Mattermost Server | 10.3.x <= 10.3.2 |
| Mattermost Server | 10.2.x <= 10.2.2 |
| Mattermost Server | 9.11.x <= 9.11.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.
- Vendors
- mattermost
- Products
- mattermost server
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.