cbcvebase.

Mattermost Desktop vulnerabilities

28 known vulnerabilities affecting mattermost/mattermost_desktop.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM16LOW6

Vulnerabilities

Page 2 of 2
CVE-2018-21265P4MEDIUMCVSS 5.3fixed in 4.0.02020-06-19
CVE-2018-21265 [MEDIUM] CWE-732 CVE-2018-21265: An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).
nvd
CVE-2023-5339P4MEDIUMCVSS 5.5≤ 5.4.02023-10-17
CVE-2023-5339 [MEDIUM] CWE-200 CVE-2023-5339: Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
nvd
CVE-2026-4643P4LOWCVSS 3.5≤ 5.4.13.0≥ 6.0.0, ≤ 6.0.1+1 more2026-05-18
CVE-2026-4643 [LOW] CWE-754 CVE-2026-4643: Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from cl Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, leading to a denial of service condition at the client level.
nvd
CVE-2025-1398P4LOWCVSS 3.3fixed in 5.11.02025-03-17
CVE-2025-1398 [LOW] CWE-426 CVE-2025-1398: Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which al Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
nvd
CVE-2025-13326P4LOWCVSS 3.9fixed in 6.0.02025-12-17
CVE-2025-13326 [LOW] CWE-693 CVE-2025-13326: Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
nvd
CVE-2025-13321P4LOWCVSS 3.3fixed in 6.0.02025-12-17
CVE-2025-13321 [LOW] CWE-532 CVE-2025-13321: Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs a Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
nvd
CVE-2024-36287P4LOWCVSS 3.3≤ 5.7.02024-06-14
CVE-2024-36287 [LOW] CWE-693 CVE-2024-36287: Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows fo Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
nvd
CVE-2023-5920P4LOWCVSS 3.3fixed in 5.5.1≤ 5.5.02023-11-02
CVE-2023-5920 [LOW] CWE-200 CVE-2023-5920: Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by ma Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
nvd
Mattermost Desktop vulnerabilities | cvebase