CVE-2025-36530

Source
https://cve.org/CVERecord?id=CVE-2025-36530
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-36530.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-36530
Aliases
Published
2025-08-21T07:11:43.241Z
Modified
2026-08-12T03:51:10.433674131Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Import Path Traversal Enables Unauthorized Unsigned Plugin Installation
Details

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/36xxx/CVE-2025-36530.json",
    "cna_assigner": "Mattermost",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "10.9.0"
                },
                {
                    "last_affected": "10.9.1"
                },
                {
                    "introduced": "10.8.0"
                },
                {
                    "last_affected": "10.8.3"
                },
                {
                    "introduced": "10.5.0"
                },
                {
                    "last_affected": "10.5.8"
                },
                {
                    "introduced": "9.11.0"
                },
                {
                    "last_affected": "9.11.17"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mattermost/mattermost

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "9.11.0"
        },
        {
            "fixed": "9.11.18"
        },
        {
            "introduced": "10.5.0"
        },
        {
            "fixed": "10.5.9"
        },
        {
            "introduced": "10.8.0"
        },
        {
            "fixed": "10.8.4"
        },
        {
            "introduced": "10.9.0"
        },
        {
            "fixed": "10.9.2"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

@mattermost/client@10.*
@mattermost/client@10.5.0
@mattermost/client@10.8.0
@mattermost/client@9.*
@mattermost/client@9.11.0
@mattermost/types@10.*
@mattermost/types@10.5.0
@mattermost/types@10.8.0
@mattermost/types@9.*
@mattermost/types@9.11.0
mattermost-redux@10.*
mattermost-redux@10.8.0
v10.*
v10.5.0
v10.5.0-rc6
v10.5.1
v10.5.1-rc1
v10.5.1-rc2
v10.5.2
v10.5.3
v10.5.3-rc1
v10.5.4
v10.5.4-rc1
v10.5.4-rc2
v10.5.5
v10.5.5-rc1
v10.5.6
v10.5.6-rc1
v10.5.7
v10.5.8
v10.5.8-rc1
v10.5.9-rc1
v10.5.9-rc2
v10.5.9-rc3
v10.5.9-rc4
v10.8.0
v10.8.0-rc3
v10.8.1
v10.8.2
v10.8.3
v10.8.4-rc1
v10.8.4-rc2
v10.8.4-rc3
v10.8.4-rc4
v10.9.0
v10.9.0-rc4
v10.9.1
v9.*
v9.11.0
v9.11.0-rc3
v9.11.1
v9.11.1-rc1
v9.11.10
v9.11.10-rc1
v9.11.11
v9.11.11-rc1
v9.11.12
v9.11.12-rc1
v9.11.13
v9.11.13-rc1
v9.11.14
v9.11.15
v9.11.16
v9.11.16-rc1
v9.11.17
v9.11.17-rc1
v9.11.18-rc1
v9.11.18-rc2
v9.11.18-rc3
v9.11.18-rc4
v9.11.2
v9.11.2-rc1
v9.11.2-rc2
v9.11.3
v9.11.3-rc1
v9.11.3-rc2
v9.11.4
v9.11.4-rc1
v9.11.5
v9.11.5-rc1
v9.11.6
v9.11.6-rc1
v9.11.6-rc2
v9.11.7
v9.11.7-rc1
v9.11.7-rc2
v9.11.7-rc3
v9.11.8
v9.11.9
v9.11.9-rc1
v9.11.9-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-36530.json"