CVE-2025-49222 | Mattermost up to 9.11.17/10.5.8/10.8.3/10.9.2/10.10.0 Non-Attachment File unrestricted upload (Nessus ID 264626 / WID-SEC-2025-1625)
A vulnerability identified as critical has been detected in Mattermost up to 9.11.17/10.5.8/10.8.3/10.9.2/10.10.0. This vulnerability affects unknown code of the component Non-Attachment File Handler. This manipulation causes unrestricted upload.
This vulnerability is tracked as CVE-2025-49222. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.