{"id":"CVE-2017-18876","aliases":["GHSA-hjqh-j6rj-gh8q","GO-2025-4187"],"url":"https://o3.security/vulnerability/CVE-2017-18876","summary":"Mattermost Server is vulnerable to Path Traversal when files are stored locally","details":"An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.","published":"2020-06-19T17:15:12.177Z","modified":"2026-08-27T08:19:00.305712Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.00862,"percentile":0.5623,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server","fixedVersion":"4.1.2-0.20171004201910-6be8113eb60c"},{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server","fixedVersion":"4.2.1-0.20171004194140-6d3cb2ce07fc"},{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server","fixedVersion":"4.3.0"}],"fix":{"url":"https://github.com/mattermost/mattermost/commit/6be8113eb60cf5ddd2dc1c3f4db05cae0c183086","label":"mattermost/mattermost@6be8113"},"references":[{"type":"ADVISORY","url":"https://mattermost.com/security-updates/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-18876"},{"type":"WEB","url":"https://github.com/mattermost/mattermost/commit/6be8113eb60cf5ddd2dc1c3f4db05cae0c183086"},{"type":"WEB","url":"https://github.com/mattermost/mattermost/commit/6d3cb2ce07fc799832081e93843b405b390057fa"},{"type":"WEB","url":"https://github.com/mattermost/mattermost/commit/fadd9514f6e71590aba781a7035e1de4150137b0"},{"type":"PACKAGE","url":"https://github.com/mattermost/mattermost"},{"type":"WEB","url":"https://mattermost.com/security-updates"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:19:00.305712Z"}}