Vulnerability Description
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost Server | >= 9.11.0, < 9.11.16 |
Related Weaknesses (CWE)
References
- https://mattermost.com/security-updatesVendor Advisory
FAQ
What is CVE-2025-4981?
CVE-2025-4981 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to wr...
How severe is CVE-2025-4981?
CVE-2025-4981 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-4981?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost Server.