Fiche vulnérabilité
CVE-2025-36530 : faille moyenne mattermost mattermost server (CVSS 4.9)
Description
Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.
En bref
- Sévérité
- Moyenne (CVSS 4.9)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 21 août 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- mattermost mattermost server