CVE-2025-1398
published 2025-03-17CVE-2025-1398: Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency…
PriorityP413low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.16%
5.9th percentile
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | <= 5.10.0 | — |
| mattermost | mattermost_desktop | < 5.11.0 | 5.11.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
ghsa·2025-03-17
CVE-2025-1398 [LOW] CWE-426 Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
OSV
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
osv·2025-03-17
CVE-2025-1398 [LOW] Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-17
Published