CVE-2025-9081: Mattermost boards plugin fails to restrict download access to files
(updated )
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration
References
- github.com/advisories/GHSA-f72g-52v7-mg3p
- github.com/mattermost/mattermost-plugin-boards
- github.com/mattermost/mattermost-plugin-boards/commit/3f3e3becfe1d66db0d0f4fd235f04afd6e1ec40b
- github.com/mattermost/mattermost-plugin-boards/pull/114
- mattermost.com/security-updates
- nvd.nist.gov/vuln/detail/CVE-2025-9081
Code Behaviors & Features
Detect and mitigate CVE-2025-9081 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →