Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qq9-cqj8-82w4

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target server's filestore via path traversal sequences in the filename field.. Mattermost Advisory ID: MMSA-2026-00661

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target server's filestore via path traversal sequences in the filename field.. Mattermost Advisory ID: MMSA-2026-00661

EPSS

Процентиль: 23%
0.00305
Низкий

7.6 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.6
nvd
около 2 месяцев назад

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target server's filestore via path traversal sequences in the filename field.. Mattermost Advisory ID: MMSA-2026-00661

CVSS3: 7.6
debian
около 2 месяцев назад

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10. ...

EPSS

Процентиль: 23%
0.00305
Низкий

7.6 High

CVSS3

Дефекты

CWE-22