CVE-2025-9079: Admin RCE via prepackaged plugins by way of misconfigured imports directory
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to prepackaged plugins directory
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9079?
CVE-2025-9079 is considered a high severity vulnerability due to its potential for arbitrary code execution by malicious plugins.
How do I fix CVE-2025-9079?
To fix CVE-2025-9079, upgrade Mattermost to a version that is not vulnerable, specifically past versions 10.8.3, 10.5.8, 9.11.17, 10.10.1, and 10.9.3.
What versions of Mattermost are affected by CVE-2025-9079?
CVE-2025-9079 affects Mattermost versions 10.8.x up to 10.8.3, 10.5.x up to 10.5.8, 9.11.x up to 9.11.17, 10.10.x up to 10.10.1, and 10.9.x up to 10.9.3.
What type of attack does CVE-2025-9079 allow?
CVE-2025-9079 allows admin users to execute arbitrary code via the upload of malicious plugins to the prepackaged plugins directory.
Who is affected by CVE-2025-9079?
Admins using vulnerable versions of Mattermost who have the ability to upload plugins are at risk due to CVE-2025-9079.