CVE-2023-6458: Mattermost Server
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.
Affected products
- Mattermost Mattermost Server: before 7.8.14 (fixed in 7.8.14); from 8.0.0, before 8.1.5 (fixed in 8.1.5); from 9.0.0, before 9.0.3 (fixed in 9.0.3); from 9.1.0, before 9.1.2 (fixed in 9.1.2)
Published 2023-12-06. Last modified 2026-06-17.