
We found results for “”
CVE-2025-6465
Good to know:


Date: August 21, 2025
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
Severity Score
Severity Score
Weakness Type (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22Top Fix

Upgrade Version
Upgrade to version github.com/mattermost/mattermost-server - v10.8.4;github.com/mattermost/mattermost-server - v10.5.9;github.com/mattermost/mattermost-server - v10.9.4;github.com/mattermost/mattermost-server - v10.10.1;https://github.com/mattermost/mattermost.git - v10.8.4;https://github.com/mattermost/mattermost.git - v10.5.9;https://github.com/mattermost/mattermost.git - v10.10.1;https://github.com/mattermost/mattermost.git - v10.9.4
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | LOW |
Availability (A): | NONE |