Desktop
by Mattermost
Source repositories
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-11064 | Cri | 0.57 | 9.8 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection. | ||
| CVE-2019-20856 | Cri | 0.57 | 9.8 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection. | ||
| CVE-2019-20861 | Hig | 0.50 | 8.8 | 0.02 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link. | ||
| CVE-2020-14456 | Hig | 0.47 | 7.3 | 0.00 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006. | ||
| CVE-2026-8683 | Med | 0.42 | 6.5 | 0.00 | Jun 15, 2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost… | ||
| CVE-2020-14455 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007. | ||
| CVE-2026-6517 | Med | 0.41 | 6.3 | 0.00 | Jun 15, 2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via… | ||
| CVE-2020-14454 | Med | 0.40 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008. | ||
| CVE-2025-13326 | Low | 0.25 | 3.9 | 0.00 | Dec 17, 2025 | Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder. | ||
| CVE-2026-12284 | Low | 0.17 | 3.7 | 0.00 | Sep 17, 2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different… | ||
| CVE-2025-13321 | Low | 0.14 | 3.3 | 0.00 | Dec 17, 2025 | Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs. |
- risk 0.57cvss 9.8epss 0.01
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
- risk 0.57cvss 9.8epss 0.01
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
- risk 0.50cvss 8.8epss 0.02
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.
- risk 0.47cvss 7.3epss 0.00
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
- risk 0.42cvss 6.5epss 0.00
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.
- risk 0.41cvss 6.3epss 0.00
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
- risk 0.25cvss 3.9epss 0.00
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
- risk 0.17cvss 3.7epss 0.00
Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different…
- risk 0.14cvss 3.3epss 0.00
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.