CVE-2025-9079 is a critical path traversal vulnerability affecting Mattermost Server versions 10.8.3 and earlier, 10.5.8 and earlier, 9.11.17 and earlier, 10.10.1 and earlier, and 10.9.3 and earlier. This flaw allows authenticated administrative users to execute arbitrary code by uploading a malicious plugin to the prepackaged plugins directory due to improper validation of the import directory path. With a CVSS score of 7.2 (High), the vulnerability poses a significant risk, enabling full compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.10.0, <= 10.10.1CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.5.0, <= 10.5.8CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.8.0, <= 10.8.3CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.9.0, <= 10.9.3CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 9.11.0, <= 9.11.17CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.