CVE-2025-6465
21.08.2025, 17:15
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Vulnerability Media Exposure
References