CVE-2025-6465
published 2025-08-21CVE-2025-6465: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.75%
51.1th percentile
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.10.0 < 10.10.1 | 10.10.1 |
| github.com | mattermost_mattermost-server | >= 10.10.0+incompatible < 10.10.1+incompatible | 10.10.1+incompatible |
| github.com | mattermost_mattermost-server | >= 10.5.0 < 10.5.9 | 10.5.9 |
| github.com | mattermost_mattermost-server | >= 10.5.0+incompatible < 10.5.9+incompatible | 10.5.9+incompatible |
| github.com | mattermost_mattermost-server | >= 10.8.0 < 10.8.4 | 10.8.4 |
| github.com | mattermost_mattermost-server | >= 10.8.0+incompatible < 10.8.4+incompatible | 10.8.4+incompatible |
| github.com | mattermost_mattermost-server | >= 10.9.0 < 10.9.4 | 10.9.4 |
| github.com | mattermost_mattermost-server | >= 10.9.0+incompatible < 10.9.4+incompatible | 10.9.4+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20250708173752-d6b35c41f0ae5 | 8.0.0-20250708173752-d6b35c41f0ae5 |
| mattermost | mattermost | — | — |
| mattermost | mattermost | 10.5.0 – 10.5.8 | — |
| mattermost | mattermost | 10.8.0 – 10.8.3 | — |
| mattermost | mattermost | 10.9.0 – 10.9.3 | — |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 10.5.0 < 10.5.9 | 10.5.9 |
| mattermost | mattermost_server | >= 10.8.0 < 10.8.4 | 10.8.4 |
| mattermost | mattermost_server | >= 10.9.0 < 10.9.4 | 10.9.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server
osv·2025-08-29
CVE-2025-6465 Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server
Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server
Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5.
GHSA
Mattermost Fails to Sanitize File Names
ghsa·2025-08-21
CVE-2025-6465 [MEDIUM] CWE-22 Mattermost Fails to Sanitize File Names
Mattermost Fails to Sanitize File Names
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
OSV
Mattermost Fails to Sanitize File Names
osv·2025-08-21
CVE-2025-6465 [MEDIUM] Mattermost Fails to Sanitize File Names
Mattermost Fails to Sanitize File Names
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-21
Published