CVE-2025-4981CRITICAL 9.9EPSS p46.3%

CVE-2025-4981CVE-2025-4981

Description

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.

Scoring

CVSS 3.19.9 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS0.65% probability of exploitation · percentile 46.3% · 2026-06-18T12:00:27Z
Published2025-06-20
Last modified2025-07-08

Underlying weaknesses· 1

CWE-427

References

  1. https://mattermost.com/security-updates

1

TypeTargetConfidenceTier
WeaknessUncontrolled Search Path Elementcwe-4270%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-6957
CVE
CVE-2026-4858
CVE
CVE-2025-25068
CVE
CVE-2025-14273
CVE
CVE-2026-4915
CVE
CVE-2025-25274
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.