Mattermost Desktop vulnerabilities
24 known vulnerabilities affecting mattermost/mattermost_desktop.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM14LOW5
Vulnerabilities
Page 1 of 2
CVE-2026-1628MEDIUMCVSS 4.6fixed in 5.13.42026-03-02
CVE-2026-1628 [MEDIUM] CWE-829 CVE-2026-1628: Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596
nvd
CVE-2026-1046MEDIUMCVSS 6.5≥ 5.13.2, < 5.13.3≥ 6.0.0, < 6.0.32026-02-16
CVE-2026-1046 [HIGH] CWE-939 CVE-2026-1046: Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a mali
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
nvd
CVE-2025-13321LOWCVSS 3.3fixed in 6.0.02025-12-17
CVE-2025-13321 [LOW] CWE-532 CVE-2025-13321: Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs a
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
nvd
CVE-2025-13326LOWCVSS 3.9fixed in 6.0.02025-12-17
CVE-2025-13326 [LOW] CWE-693 CVE-2025-13326: Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
nvd
CVE-2025-55035MEDIUMCVSS 6.1fixed in 5.13.1.02025-10-16
CVE-2025-55035 [MEDIUM] CWE-754 CVE-2025-55035: Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that st
Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a m
nvd
CVE-2025-58084MEDIUMCVSS 6.5fixed in 5.13.1.02025-10-13
CVE-2025-58084 [LOW] CWE-1287 CVE-2025-58084: Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermos
Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
nvd
CVE-2025-1398LOWCVSS 3.3fixed in 5.11.02025-03-17
CVE-2025-1398 [LOW] CWE-426 CVE-2025-1398: Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which al
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
nvd
CVE-2024-39613HIGHCVSS 7.8fixed in 5.9.02024-09-16
CVE-2024-39613 [MEDIUM] CWE-427 CVE-2024-39613: Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
nvd
CVE-2024-39772MEDIUMCVSS 5.3fixed in 5.9.02024-09-16
CVE-2024-39772 [LOW] CWE-284 CVE-2024-39772: Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
nvd
CVE-2024-45835MEDIUMCVSS 6.5fixed in 5.9.02024-09-16
CVE-2024-45835 [LOW] CWE-693 CVE-2024-45835: Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows a
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
nvd
CVE-2024-37182MEDIUMCVSS 6.1≤ 5.7.02024-06-14
CVE-2024-37182 [MEDIUM] CWE-693 CVE-2024-37182: Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening externa
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
nvd
CVE-2024-36287LOWCVSS 3.3≤ 5.7.02024-06-14
CVE-2024-36287 [LOW] CWE-693 CVE-2024-36287: Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows fo
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
nvd
CVE-2023-5875MEDIUMCVSS 5.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5875 [LOW] CWE-693 CVE-2023-5875: Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain s
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
cvelistv5nvd
CVE-2023-5876MEDIUMCVSS 5.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5876 [LOW] CWE-400 CVE-2023-5876: Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker i
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
cvelistv5nvd
CVE-2023-5920LOWCVSS 3.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5920 [LOW] CWE-200 CVE-2023-5920: Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by ma
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
cvelistv5nvd
CVE-2023-5339MEDIUMCVSS 5.5≤ 5.4.02023-10-17
CVE-2023-5339 [MEDIUM] CWE-200 CVE-2023-5339: Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
nvd
CVE-2023-2000MEDIUMCVSS 5.4≤ 5.2.22023-05-02
CVE-2023-2000 [MEDIUM] CWE-601 CVE-2023-2000: Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitra
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
nvd
CVE-2019-20856CRITICALCVSS 9.8fixed in 4.3.02020-06-19
CVE-2019-20856 [CRITICAL] CWE-427 CVE-2019-20856: An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
nvd
CVE-2016-11064CRITICALCVSS 9.8fixed in 3.4.02020-06-19
CVE-2016-11064 [CRITICAL] CWE-94 CVE-2016-11064: An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code vi
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
nvd
CVE-2019-20861HIGHCVSS 8.8fixed in 4.2.22020-06-19
CVE-2019-20861 [HIGH] CVE-2019-20861: An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbit
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.
nvd
1 / 2Next →