CVE-2025-20051: Arbitrary file read via block duplication in Mattermost Boards
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20051?
CVE-2025-20051 has a medium severity rating due to its potential for unauthorized file access.
How do I fix CVE-2025-20051?
To fix CVE-2025-20051, update your Mattermost version to 10.4.2, 10.3.3, 10.2.3, or 9.11.8.
What products are affected by CVE-2025-20051?
CVE-2025-20051 affects Mattermost versions 10.4.x through 10.4.1, 9.11.x through 9.11.7, 10.3.x through 10.3.2, and 10.2.x through 10.2.2.
What happens if I am vulnerable to CVE-2025-20051?
If you are vulnerable to CVE-2025-20051, an attacker could exploit this issue to read arbitrary files from your system.
When was CVE-2025-20051 reported?
CVE-2025-20051 was reported in early 2025.