VYPR

Mattermost Desktop App

by Mattermost

Source repositories

CVEs (18)

  • CVE-2016-11064CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

  • CVE-2019-20856CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.

  • CVE-2019-20861HigJun 19, 2020
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.

  • CVE-2020-14456HigJun 19, 2020
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

  • CVE-2026-8683MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost…

  • CVE-2020-14455MedJun 19, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.

  • CVE-2026-6517MedJun 15, 2026
    risk 0.41cvss 6.3epss 0.00

    Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via…

  • CVE-2025-55035MedOct 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the…

  • CVE-2020-14454MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.

  • CVE-2023-2000MedMay 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website

  • CVE-2018-21265MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

  • CVE-2023-5339MedOct 17, 2023
    risk 0.31cvss 4.7epss 0.00

    Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

  • CVE-2025-13326LowDec 17, 2025
    risk 0.25cvss 3.9epss 0.00

    Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.

  • CVE-2023-5875LowNov 2, 2023
    risk 0.24cvss 3.7epss 0.00

    Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

  • CVE-2026-4643LowMay 18, 2026
    risk 0.23cvss 3.5epss 0.00

    Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the…

  • CVE-2025-58084LowOct 13, 2025
    risk 0.23cvss 3.5epss 0.00

    Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.

  • CVE-2023-5876LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.

  • CVE-2023-5920LowNov 2, 2023
    risk 0.19cvss 2.9epss 0.00

    Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.