CVE-2025-25279
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Feb 24, 2025
CWE ID 22
Summary
CVE-2025-25279 is a vulnerability affecting Mattermost versions 10.4.x up to 10.4.1, 9.11.x up to 9.11.7, 10.3.x up to 10.3.2, and 10.2.x up to 10.2.2. An attacker can exploit this issue by importing a specially crafted archive into the affected system. The vulnerability lies in the failure to validate board blocks, which could result in the unintended execution of arbitrary file reads. This poses a significant risk to the security of the affected Mattermost installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.