Junglewise Threat Intelligence

CVE-2026-6961: Mattermost path traversal in shared channel file sync

CVE-2026-6961 · Severity: high · CVSS 7.6 · Published 2026-06-12

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost is a team collaboration platform that allows organizations to securely share files and communicate. When Mattermost servers are federated (connected to other Mattermost instances), they synchronize shared channel files without properly validating filenames from peer servers. An attacker who controls a federated Mattermost server can craft malicious filenames containing path traversal sequences (e.g., "../../") to write files to arbitrary locations on the target server's disk, potentially compromising data integrity or enabling further attacks.

Technical details

The vulnerability is a path traversal (CWE-22) in the shared channel file synchronization mechanism. When federated peers send FileInfo objects during shared channel file sync, the receiving server fails to sanitize the FileInfo.Name field before using it to construct file paths. An attacker who has control over a federated Mattermost server can inject path traversal sequences (e.g., "../" or "..\") into the filename field, causing files to be written outside the intended filestore directory. The attack requires high privileges (federation server admin or equivalent) but operates over the network. The impact is limited to file integrity (no confidentiality impact reported). Patches sanitize filenames using filepath.Base, Unicode normalization (NFC), ASCII control character stripping, and path length validation, available in versions 11.6.2, 11.5.5, 10.11.17 and later.

Affected products

  • Mattermost Mattermost Server 11.6.0-11.6.1, 11.5.0-11.5.4, 10.11.0-10.11.15

Timeline

  • 2026-06-12: disclosed: Vulnerability published in GitHub Advisory Database
  • 2026-04-23: patched: Fix merged upstream (PR #36223)
  • 2026-04-24: patched: Patch backported to release branches (11.7, 11.6, 11.5, 10.11)

References

Related threats