Mattermost Arbitrary File Read Vulnerability in Boards Import Feature

Vulnerability

A vulnerability exists in Mattermost versions 10.4.x through 10.4.1, 9.11.x through 9.11.7, 10.3.x through 10.3.2, and 10.2.x through 10.2.2. These versions fail to properly validate board blocks when importing boards, allowing an attacker to read any arbitrary file on the system. This is achieved by importing and exporting a specially crafted import archive in the Boards feature.

Impact

Exploitation of this vulnerability allows for arbitrary file read on the server where Mattermost is running.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
3.3
exploitability
5.0
remediation
0.0
relevance
0.0
threat
1.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.