CVE-2025-25279 is an arbitrary file read vulnerability affecting multiple versions of Mattermost server, specifically 10.4.x, 9.11.x, 10.3.x, and 10.2.x. This flaw allows an attacker to read any file on the system by importing a specially crafted archive in Boards due to improper validation of board blocks. Rated 7.5 High severity, it has a network attack vector, low complexity, and requires no privileges or user interaction, leading to high confidentiality impact. Although not actively exploited or having public exploit code, its high EPSS score (0.612) and "Hot List: Active" status indicate a significant potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.11.0, < 9.11.8CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 10.2.0, < 10.2.3CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 10.3.0, < 10.3.3CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 10.4.0, < 10.4.2CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 10.2.0, <= 10.2.2CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.