VDB
GO-2025-3769
GO-2025-3769
PUBLISHED
Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | mattermost/mattermost-server/v5 | 0, 0 |
| github.com | mattermost/mattermost-server/v6 | 0, 0 |
| github.com | mattermost/mattermost/server/v8 | 0, 0 |
| github.com | mattermost/mattermost-server | 10.5.0+incompatible, 10.7.0+incompatible, 10.8.0+incompatible |
Timeline
- Jul 28, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory