CVE-2025-1398Untrusted Search Path in Desktop

Severity
3.3LOWNVD
EPSS
0.0%
top 90.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17

Description

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection2025-03-17
CVEList
macOS TCC Bypass via Code Injection2025-03-17
OSV
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection2025-03-17
CVE-2025-1398 — Untrusted Search Path in Desktop | cvebase