PT-2026-52708 · Mattermost · Mattermost
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
github.com/mattermost/mattermost/server/public versions prior to 0.1.22
Description
The software fails to validate path parameters when constructing API route paths. This allows an attacker to redirect API calls to unintended endpoints by using crafted IDs that include path traversal components, which are sequences of characters used to access files or directories outside the intended folder.
Recommendations
Update github.com/mattermost/mattermost/server/public to version 0.1.22 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost