Executive brief
A vulnerability in a core Mattermost software component allows an attacker to manipulate API requests. By using specially crafted identification strings, an authorized user could redirect internal system calls to unintended locations. This could lead to unauthorized access to data or the performance of unintended actions within the Mattermost platform.
Technical details
A path traversal vulnerability (CWE-22) exists in the Mattermost Go module 'github.com/mattermost/mattermost/server/public'. The root cause is a failure to properly sanitize or validate path parameters when the module constructs API route paths. A remote attacker with low-level authentication can provide crafted IDs containing path traversal sequences (e.g., '../') to redirect API calls to unintended endpoints. This can result in unauthorized information disclosure or unauthorized modification of data. The issue is resolved in version v0.1.22 of the module.
Affected products
- Mattermost github.com/mattermost/mattermost/server/public < v0.1.22
Timeline
- 2026-06-26: advisory: NVD publication date
- 2026-06-26: disclosed: Initial disclosure by Mattermost