CVE-2025-25279

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Feb 24, 2025
CWE ID 22

Summary

CVE-2025-25279 is a vulnerability affecting Mattermost versions 10.4.x up to 10.4.1, 9.11.x up to 9.11.7, 10.3.x up to 10.3.2, and 10.2.x up to 10.2.2. An attacker can exploit this issue by importing a specially crafted archive into the affected system. The vulnerability lies in the failure to validate board blocks, which could result in the unintended execution of arbitrary file reads. This poses a significant risk to the security of the affected Mattermost installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.