VDB
GO-2025-3977
GO-2025-3977
PUBLISHED
CVSS 8.699999809265137 HIGH
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | mattermost/mattermost-server | 10.5.0+incompatible, 10.10.0+incompatible, 10.9.0+incompatible |
| github.com | mattermost/mattermost-server/v6 | 0, 0 |
| github.com | mattermost/mattermost/server/v8 | 0, 0 |
| github.com | mattermost/mattermost-server/v5 | 0, 0 |
Timeline
- Sep 24, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/advisories/GHSA-qx3f-6vq3-8j8m advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9079 advisory
- https://github.com/mattermost/mattermost/commit/047a2c64071749367fe02d2162f6103a3d31a883 url
- https://github.com/mattermost/mattermost/commit/439464883aa16a329c23cd6274c4cca7e88e238f url
- https://github.com/mattermost/mattermost/commit/4ff68eea0a3f3777032d31a1a82f4b1fb492a1ac url
- https://github.com/mattermost/mattermost/commit/96665b9b98a17534fcd515982a2eb26950581e41 url
- https://github.com/mattermost/mattermost/commit/a8fa77f107efe83f09a779f8e67cbecf236b0032 url
- https://github.com/mattermost/mattermost/commit/b38e2eccda182212a8032539658723c7d87e0b7e url
- https://mattermost.com/security-updates url