CVE-2025-25279: Arbitrary file read in Mattermost Boards via import & export board archive
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.4.2 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.3.3 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.2.3 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 9.11.8 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 8.0.0-20250122165010-4ed702ccff4e - Upgrade
Upgrade
mattermost/boards-pluginto a version that resolves this vulnerability.Fixed in v9.0.5 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.5.0 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.4.2 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 9.11.8 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.3.3 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25279?
CVE-2025-25279 is rated as a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2025-25279?
To fix CVE-2025-25279, upgrade to Mattermost versions 10.4.2, 10.3.3, 10.2.3, or 9.11.8.
What versions of Mattermost are affected by CVE-2025-25279?
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, and 10.2.x <= 10.2.2 are affected by CVE-2025-25279.
What causes CVE-2025-25279?
CVE-2025-25279 is caused by improper validation of board blocks during the import process.
Can CVE-2025-25279 lead to data breaches?
Yes, CVE-2025-25279 can potentially allow attackers to read arbitrary files on the system, leading to data breaches.