Medium severity4.7NVD Advisory· Published Jun 14, 2024· Updated Jun 17, 2026
CVE-2024-37182
CVE-2024-37182
Description
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mattermost-desktopnpm | < 5.8.0 | 5.8.0 |
Affected products
3- cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*Range: <=5.7.0
- Range: 0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-hvxg-77mg-vrvpghsaADVISORY
- mattermost.com/security-updatesnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-37182ghsaADVISORY
- github.com/mattermost/desktop/commit/1c9fc719dc2b74495a05f7ebc90e92e7daa03e6dghsaWEB
News mentions
0No linked articles in our index yet.