Mattermost Desktop vulnerabilities

24 known vulnerabilities affecting mattermost/mattermost_desktop.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM14LOW5

Vulnerabilities

Page 1 of 2
CVE-2026-1628MEDIUMCVSS 4.6fixed in 5.13.42026-03-02
CVE-2026-1628 [MEDIUM] CWE-829 CVE-2026-1628: Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596
nvd
CVE-2026-1046MEDIUMCVSS 6.5≥ 5.13.2, < 5.13.3≥ 6.0.0, < 6.0.32026-02-16
CVE-2026-1046 [HIGH] CWE-939 CVE-2026-1046: Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a mali Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
nvd
CVE-2025-13321LOWCVSS 3.3fixed in 6.0.02025-12-17
CVE-2025-13321 [LOW] CWE-532 CVE-2025-13321: Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs a Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
nvd
CVE-2025-13326LOWCVSS 3.9fixed in 6.0.02025-12-17
CVE-2025-13326 [LOW] CWE-693 CVE-2025-13326: Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
nvd
CVE-2025-55035MEDIUMCVSS 6.1fixed in 5.13.1.02025-10-16
CVE-2025-55035 [MEDIUM] CWE-754 CVE-2025-55035: Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that st Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a m
nvd
CVE-2025-58084MEDIUMCVSS 6.5fixed in 5.13.1.02025-10-13
CVE-2025-58084 [LOW] CWE-1287 CVE-2025-58084: Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermos Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
nvd
CVE-2025-1398LOWCVSS 3.3fixed in 5.11.02025-03-17
CVE-2025-1398 [LOW] CWE-426 CVE-2025-1398: Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which al Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
nvd
CVE-2024-39613HIGHCVSS 7.8fixed in 5.9.02024-09-16
CVE-2024-39613 [MEDIUM] CWE-427 CVE-2024-39613: Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
nvd
CVE-2024-39772MEDIUMCVSS 5.3fixed in 5.9.02024-09-16
CVE-2024-39772 [LOW] CWE-284 CVE-2024-39772: Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
nvd
CVE-2024-45835MEDIUMCVSS 6.5fixed in 5.9.02024-09-16
CVE-2024-45835 [LOW] CWE-693 CVE-2024-45835: Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows a Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
nvd
CVE-2024-37182MEDIUMCVSS 6.1≤ 5.7.02024-06-14
CVE-2024-37182 [MEDIUM] CWE-693 CVE-2024-37182: Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening externa Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
nvd
CVE-2024-36287LOWCVSS 3.3≤ 5.7.02024-06-14
CVE-2024-36287 [LOW] CWE-693 CVE-2024-36287: Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows fo Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
nvd
CVE-2023-5875MEDIUMCVSS 5.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5875 [LOW] CWE-693 CVE-2023-5875: Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain s Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
cvelistv5nvd
CVE-2023-5876MEDIUMCVSS 5.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5876 [LOW] CWE-400 CVE-2023-5876: Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker i Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
cvelistv5nvd
CVE-2023-5920LOWCVSS 3.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5920 [LOW] CWE-200 CVE-2023-5920: Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by ma Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
cvelistv5nvd
CVE-2023-5339MEDIUMCVSS 5.5≤ 5.4.02023-10-17
CVE-2023-5339 [MEDIUM] CWE-200 CVE-2023-5339: Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
nvd
CVE-2023-2000MEDIUMCVSS 5.4≤ 5.2.22023-05-02
CVE-2023-2000 [MEDIUM] CWE-601 CVE-2023-2000: Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitra Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
nvd
CVE-2019-20856CRITICALCVSS 9.8fixed in 4.3.02020-06-19
CVE-2019-20856 [CRITICAL] CWE-427 CVE-2019-20856: An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection. An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
nvd
CVE-2016-11064CRITICALCVSS 9.8fixed in 3.4.02020-06-19
CVE-2016-11064 [CRITICAL] CWE-94 CVE-2016-11064: An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code vi An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
nvd
CVE-2019-20861HIGHCVSS 8.8fixed in 4.2.22020-06-19
CVE-2019-20861 [HIGH] CVE-2019-20861: An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbit An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.
nvd