CVE-2025-13321
published 2025-12-17CVE-2025-13321: Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.10%
1.2th percentile
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | <= 6.0.0 | — |
| mattermost | mattermost_desktop | < 6.0.0 | 6.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost Desktop App exposes sensitive information in its application logs
ghsa·2025-12-17
CVE-2025-13321 [LOW] CWE-532 Mattermost Desktop App exposes sensitive information in its application logs
Mattermost Desktop App exposes sensitive information in its application logs
Mattermost Desktop App versions < 6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
A fix is available for direct download via the [Mattermost Desktop](https://github.com/mattermost/desktop/releases/tag/v6.0.0) repository, but it has not been uploaded to the npm registry at time of publication.
OSV
Mattermost Desktop App exposes sensitive information in its application logs
osv·2025-12-17
CVE-2025-13321 [LOW] Mattermost Desktop App exposes sensitive information in its application logs
Mattermost Desktop App exposes sensitive information in its application logs
Mattermost Desktop App versions < 6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
A fix is available for direct download via the [Mattermost Desktop](https://github.com/mattermost/desktop/releases/tag/v6.0.0) repository, but it has not been uploaded to the npm registry at time of publication.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1628 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-1628 [LOW] CVE-2026-1628 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1628 :
Mattermost Desktop App vulnerability analysis and mitigation
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596
Source : NVD
## 4.6
Score
Published March 2, 2026
Severity MEDIUM
CNA Score 4.6
Affected Technologies
Mattermost Desktop App
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mattermost:mattermost_d
Wiz
CVE-2026-1046 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-1046 [LOW] CVE-2026-1046 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1046 :
Mattermost Desktop App vulnerability analysis and mitigation
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
Source : NVD
## 6.5
Score
Published February 16, 2026
Severity MEDIUM
CNA Score 7.6
Affected Technologies
Mattermost Desktop App
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mattermost:mattermost_desktop
Sources
Windows Severity MEDIUM Has Fix Added a
Wiz
CVE-2025-13326 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-13326 [LOW] CVE-2025-13326 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13326 :
Mattermost Desktop App vulnerability analysis and mitigation
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
Source : NVD
## 3.9
Score
Published December 17, 2025
Severity LOW
CNA Score 3.9
Affected Technologies
Mattermost Desktop App
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mattermost:mattermost_desktop
Sources
Windows Severity LOW Has Fix Added at: Dec 21, 2025
## Get a CVE risk assessment
Ge
Wiz
CVE-2025-13321 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-13321 [LOW] CVE-2025-13321 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13321 :
JavaScript vulnerability analysis and mitigation
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
Source : NVD
## 3.3
Score
Published December 17, 2025
Severity LOW
CNA Score 3.3
Affected Technologies
JavaScript
Mattermost Desktop App
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
mattermost-desktop
cpe:2.3:a:mattermost:mattermost_desktop
Sources
npm Severity LOW N
2025-12-17
Published