Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 10.11.0, 10.8.4, 10.5.9, 9.11.18, 10.9.3, 10.10.1 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25418 | Mattermost Fails to Validate Remote Cluster Upload Sessions |
Github GHSA |
GHSA-q453-638c-h4mr | Mattermost Fails to Validate Remote Cluster Upload Sessions |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Thu, 21 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Thu, 21 Aug 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arbitrary filesystem directories. | |
| Title | Mattermost Shared Channel Upload Type Validation Bypass | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-08-21T13:57:13.759Z
Reserved: 2025-07-22T07:46:53.179Z
Link: CVE-2025-49222
Updated: 2025-08-21T13:57:09.799Z
Status : Undergoing Analysis
Published: 2025-08-21T08:15:30.177
Modified: 2025-08-22T18:09:17.710
Link: CVE-2025-49222
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:30:44Z
EUVD
Github GHSA