Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it
Advisories
Source ID Title
EUVD EUVD EUVD-2025-4307 Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it
Github GHSA Github GHSA GHSA-q8p2-2hwc-jw64 Mattermost fails to restrict channel export of archived channels
Fixes

Solution

Update Mattermost to versions 10.5.0, 10.1.4, 10.4.2, 9.11.8, 10.3.3, 10.2.3 or higher. Alternatively, update the channel export plugin to v1.2.1.


Workaround

No workaround given by the vendor.

References
History

Wed, 01 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Mon, 24 Feb 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 07:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it
Title Channel export permitted on archived channel when viewing archived channels is disabled
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-02-24T11:24:41.215Z

Reserved: 2025-02-18T11:11:14.648Z

Link: CVE-2025-24526

cve-icon Vulnrichment

Updated: 2025-02-24T11:24:33.790Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-24T08:15:10.427

Modified: 2025-10-01T18:03:20.600

Link: CVE-2025-24526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:07:11Z