CVE-2025-25274: Unauthorized Command Execution in Archived Channels
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.5.1 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 9.11.9 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.3.4 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.5.0 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.3.4 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 9.11.9
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25274?
CVE-2025-25274 is considered a high severity vulnerability due to its potential for unauthorized command execution in archived channels.
How do I fix CVE-2025-25274?
To fix CVE-2025-25274, upgrade your Mattermost version to 10.4.3, 10.3.4, or 9.11.9 or later.
Who is affected by CVE-2025-25274?
CVE-2025-25274 affects Mattermost versions 10.4.x up to and including 10.4.2, 10.3.x up to and including 10.3.3, and 9.11.x up to and including 9.11.8.
What does CVE-2025-25274 exploit?
CVE-2025-25274 exploits a failure to restrict command execution in archived channels, allowing authenticated users to run commands they shouldn't be able to.
Is CVE-2025-25274 applicable to my Mattermost setup?
You should assess your Mattermost version to determine if it falls within the affected versions outlined in CVE-2025-25274.