Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6957

Опубликовано: 27 мая 2026
Источник: nvd
CVSS3: 8
CVSS3: 4.9
EPSS Низкий

Описание

Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filestore via a malicious filename delivered through the shared-channel attachment sync protocol. Mattermost Advisory ID: MMSA-2026-00659

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mattermost:legal_hold:*:*:*:*:*:mattermost:*:*
Версия до 1.1.5 (включая)

EPSS

Процентиль: 22%
0.00296
Низкий

8 High

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
github
2 месяца назад

Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filestore via a malicious filename delivered through the shared-channel attachment sync protocol. Mattermost Advisory ID: MMSA-2026-00659

EPSS

Процентиль: 22%
0.00296
Низкий

8 High

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-22