
CVE-2025-4981 - Critical RCE in Mattermost. Unpatched. CVSS 9.9. Archive upload path traversal allows arbitrary file write. Disable file uploads or restrict access immediately. #CVE #Mattermost #infosec #DevSecOps #DevOps more info: https://www.valtersit.com/cve/CVE-2025-4981/
Post summary
A newly identified, unpatched RCE vulnerability (CVE‑2025‑4981) in Mattermost allows arbitrary file writes via archive upload path traversal; users are urged to disable uploads or restrict access.

