VYPR

Mattermost Desktop App

by Mattermost

Source repositories

CVEs (31)

  • CVE-2016-11064CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

  • CVE-2019-20856CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.

  • CVE-2019-20861HigJun 19, 2020
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.

  • CVE-2026-1046HigFeb 16, 2026
    risk 0.49cvss 7.6epss 0.00

    Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577

  • CVE-2020-14456HigJun 19, 2020
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

  • CVE-2026-8683MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost…

  • CVE-2026-3471MedMay 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}.…

  • CVE-2020-14455MedJun 19, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.

  • CVE-2026-6517MedJun 15, 2026
    risk 0.41cvss 6.3epss 0.00

    Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via…

  • CVE-2025-55035MedOct 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the…

  • CVE-2020-14454MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.

  • CVE-2023-2000MedMay 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website

  • CVE-2018-21265MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

  • CVE-2023-5339MedOct 17, 2023
    risk 0.31cvss 4.7epss 0.00

    Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

  • CVE-2026-1628MedMar 2, 2026
    risk 0.30cvss 4.6epss 0.00

    Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their…

  • CVE-2024-39613MedSep 16, 2024
    risk 0.27cvss 5.3epss 0.00

    Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.

  • CVE-2025-13326LowDec 17, 2025
    risk 0.25cvss 3.9epss 0.00

    Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.

  • CVE-2024-36287LowJun 14, 2024
    risk 0.25cvss 3.8epss 0.00

    Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.

  • CVE-2024-39772LowSep 16, 2024
    risk 0.24cvss 3.7epss 0.00

    Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.

  • CVE-2024-37182MedJun 14, 2024
    risk 0.24cvss 4.7epss 0.00

    Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.

Page 1 of 2