Vulnerability Details CVE-2025-9079
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to prepackaged plugins directory
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.8%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2025-9079
-
cpe:2.3:a:mattermost:mattermost_server:10.10.0
-
cpe:2.3:a:mattermost:mattermost_server:10.5.0
-
cpe:2.3:a:mattermost:mattermost_server:10.5.1
-
cpe:2.3:a:mattermost:mattermost_server:10.5.2
-
cpe:2.3:a:mattermost:mattermost_server:10.5.3
-
cpe:2.3:a:mattermost:mattermost_server:10.5.4
-
cpe:2.3:a:mattermost:mattermost_server:10.5.5
-
cpe:2.3:a:mattermost:mattermost_server:10.5.6
-
cpe:2.3:a:mattermost:mattermost_server:10.5.7
-
cpe:2.3:a:mattermost:mattermost_server:10.5.8
-
cpe:2.3:a:mattermost:mattermost_server:10.8.0
-
cpe:2.3:a:mattermost:mattermost_server:10.8.1
-
cpe:2.3:a:mattermost:mattermost_server:10.8.2
-
cpe:2.3:a:mattermost:mattermost_server:10.8.3
-
cpe:2.3:a:mattermost:mattermost_server:10.9.0
-
cpe:2.3:a:mattermost:mattermost_server:10.9.1
-
cpe:2.3:a:mattermost:mattermost_server:10.9.2
-
cpe:2.3:a:mattermost:mattermost_server:10.9.3
-
cpe:2.3:a:mattermost:mattermost_server:9.11.0
-
cpe:2.3:a:mattermost:mattermost_server:9.11.1
-
cpe:2.3:a:mattermost:mattermost_server:9.11.10
-
cpe:2.3:a:mattermost:mattermost_server:9.11.11
-
cpe:2.3:a:mattermost:mattermost_server:9.11.12
-
cpe:2.3:a:mattermost:mattermost_server:9.11.13
-
cpe:2.3:a:mattermost:mattermost_server:9.11.14
-
cpe:2.3:a:mattermost:mattermost_server:9.11.15
-
cpe:2.3:a:mattermost:mattermost_server:9.11.16
-
cpe:2.3:a:mattermost:mattermost_server:9.11.17
-
cpe:2.3:a:mattermost:mattermost_server:9.11.2
-
cpe:2.3:a:mattermost:mattermost_server:9.11.3
-
cpe:2.3:a:mattermost:mattermost_server:9.11.4
-
cpe:2.3:a:mattermost:mattermost_server:9.11.5
-
cpe:2.3:a:mattermost:mattermost_server:9.11.6
-
cpe:2.3:a:mattermost:mattermost_server:9.11.7
-
cpe:2.3:a:mattermost:mattermost_server:9.11.8
-
cpe:2.3:a:mattermost:mattermost_server:9.11.9