cbcvebase.

Mattermost Desktop vulnerabilities

28 known vulnerabilities affecting mattermost/mattermost_desktop.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM16LOW6

Vulnerabilities

Page 1 of 2
CVE-2016-11064P3CRITICALCVSS 9.8fixed in 3.4.02020-06-19
CVE-2016-11064 [CRITICAL] CWE-94 CVE-2016-11064: An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code vi An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
nvd
CVE-2026-6517P3HIGHCVSS 7.7≤ 5.13.0≥ 6.1.0, ≤ 6.1.52026-06-15
CVE-2026-6517 [HIGH] CWE-522 CVE-2026-6517: Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which N Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MM
nvd
CVE-2019-20861P3HIGHCVSS 8.8fixed in 4.2.22020-06-19
CVE-2019-20861 [HIGH] CVE-2019-20861: An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbit An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.
nvd
CVE-2019-20856P3CRITICALCVSS 9.8fixed in 4.3.02020-06-19
CVE-2019-20856 [CRITICAL] CWE-427 CVE-2019-20856: An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection. An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
nvd
CVE-2024-39613P3HIGHCVSS 7.8fixed in 5.9.02024-09-16
CVE-2024-39613 [HIGH] CWE-427 CVE-2024-39613: Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
nvd
CVE-2020-14456P3HIGHCVSS 7.3fixed in 4.4.02020-06-19
CVE-2020-14456 [HIGH] CWE-346 CVE-2020-14456: An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
nvd
CVE-2026-1046P3MEDIUMCVSS 6.5≥ 5.13.2, < 5.13.3≥ 6.0.0, < 6.0.32026-02-16
CVE-2026-1046 [MEDIUM] CWE-939 CVE-2026-1046: Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a mali Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
nvd
CVE-2024-45835P3MEDIUMCVSS 6.5fixed in 5.9.02024-09-16
CVE-2024-45835 [MEDIUM] CWE-693 CVE-2024-45835: Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows a Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
nvd
CVE-2025-58084P4MEDIUMCVSS 6.5fixed in 5.13.1.02025-10-13
CVE-2025-58084 [MEDIUM] CWE-1287 CVE-2025-58084: Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermos Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
nvd
CVE-2026-8683P4MEDIUMCVSS 6.5≤ 5.13.0≥ 6.1.0, ≤ 6.1.52026-06-15
CVE-2026-8683 [MEDIUM] CWE-770 CVE-2026-8683: Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-00652
nvd
CVE-2020-14455P4MEDIUMCVSS 6.5fixed in 4.4.02020-06-19
CVE-2020-14455 [MEDIUM] CWE-287 CVE-2020-14455: An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authenticat An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.
nvd
CVE-2026-3471P4MEDIUMCVSS 6.5≤ 5.4.13.0≥ 6.0.0, ≤ 6.0.1+1 more2026-05-18
CVE-2026-3471 [MEDIUM] CWE-939 CVE-2026-3471: Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618
nvd
CVE-2024-37182P4MEDIUMCVSS 6.1≤ 5.7.02024-06-14
CVE-2024-37182 [MEDIUM] CWE-693 CVE-2024-37182: Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening externa Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
nvd
CVE-2025-55035P4MEDIUMCVSS 6.1fixed in 5.13.1.02025-10-16
CVE-2025-55035 [MEDIUM] CWE-754 CVE-2025-55035: Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that st Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a m
nvd
CVE-2023-2000P4MEDIUMCVSS 5.4≤ 5.2.22023-05-02
CVE-2023-2000 [MEDIUM] CWE-601 CVE-2023-2000: Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitra Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
nvd
CVE-2024-39772P4MEDIUMCVSS 5.3fixed in 5.9.02024-09-16
CVE-2024-39772 [MEDIUM] CWE-284 CVE-2024-39772: Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
nvd
CVE-2023-5876P4MEDIUMCVSS 5.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5876 [MEDIUM] CWE-400 CVE-2023-5876: Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker i Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
nvd
CVE-2023-5875P4MEDIUMCVSS 5.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5875 [MEDIUM] CWE-693 CVE-2023-5875: Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain s Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
nvd
CVE-2020-14454P4MEDIUMCVSS 6.1fixed in 4.4.02020-06-19
CVE-2020-14454 [MEDIUM] CWE-601 CVE-2020-14454: An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
nvd
CVE-2026-1628P4MEDIUMCVSS 4.6fixed in 5.13.42026-03-02
CVE-2026-1628 [MEDIUM] CWE-829 CVE-2026-1628: Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596
nvd