CyberzSOC

Publication detail
← Back to advisories & guidance

2025-006: Critical Vulnerabilities in Mattermost ↗ source

March 5, 2025 CERT-EU Advisory

Summary

If exploited, these vulnerabilities could allow an authenticated attacker to read any file on the server, or read data directly from the It is recommended to check for potential abuse, and to update vulnerable Mattermost instances. The vulnerability CVE-2025-25279, with a CVSS score of 9.9, arises due to a failure to validate board blocks during import processes. An attacker can exploit this vulnerability by importing a specially crafted archive. Upon successful exploitation, the attacker can read arbitrary files on The vulnerability CVE-2025-20051, with a CVSS score of 9.9, arises due to a failure to validate user input during the patching and duplication of a board. Maliciously crafted blocks can be used to read arbitrary files on the system by an attacker [3].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-20051 9.9 Critical Mattermost Mattermost Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicat…
CVE-2025-25279 9.9 Critical Mattermost Mattermost Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boar…
CVE-2025-24490 9.6 Critical Mattermost Mattermost Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.