« Volver al listado

Mattermost

Mattermost Desktop: vulnerabilidades y CVE

Mattermost Desktop tiene 31 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE31
Últimos 12 meses13
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-75587Baja (3.3)0.13%—17 ago 2026
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the…
CVE-2026-9602Media (6.5)0.42%—17 jul 2026
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing…
CVE-2026-8075Media (6.5)0.42%—17 jul 2026
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a…
CVE-2026-8683Media (6.5)0.36%—15 jun 2026
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a…
CVE-2026-6517Alta (7.7)0.32%—15 jun 2026
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image…
CVE-2026-4643Baja (3.5)0.29%—18 may 2026
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash…
CVE-2026-3471Media (6.5)0.33%—18 may 2026
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application…
CVE-2026-1628Media (4.6)0.14%—2 mar 2026
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted…
CVE-2026-1046Media (6.5)0.24%—16 feb 2026
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in…
CVE-2025-13326Baja (3.9)0.11%—17 dic 2025
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a…
CVE-2025-13321Baja (3.3)0.12%—17 dic 2025
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially…
CVE-2025-55035Media (6.1)0.32%—16 oct 2025
Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that…
CVE-2025-58084Media (6.5)0.30%—13 oct 2025
Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user…
CVE-2025-1398Baja (3.3)0.17%—17 mar 2025
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
CVE-2024-45835Media (6.5)0.21%—16 sept 2024
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
CVE-2024-39772Media (5.3)0.31%—16 sept 2024
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
CVE-2024-39613Alta (7.8)0.30%—16 sept 2024
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to…
CVE-2024-37182Media (6.1)0.30%—14 jun 2024
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's…
CVE-2024-36287Baja (3.3)0.19%—14 jun 2024
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
CVE-2023-5920Baja (3.3)0.19%—2 nov 2023
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
CVE-2023-5876Media (5.3)0.49%—2 nov 2023
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
CVE-2023-5875Media (5.3)0.33%—2 nov 2023
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
CVE-2023-5339Media (5.5)0.14%—17 oct 2023
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
CVE-2023-2000Media (5.4)0.36%—2 may 2023
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
CVE-2016-11064Crítica (9.8)1.3%—19 jun 2020
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
CVE-2018-21265Media (5.3)0.77%—19 jun 2020
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).
CVE-2019-20861Alta (8.8)1.7%—19 jun 2020
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.
CVE-2019-20856Crítica (9.8)1.4%—19 jun 2020
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
CVE-2020-14456Alta (7.3)0.43%—19 jun 2020
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
CVE-2020-14455Media (6.5)1.2%—19 jun 2020
An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services1
  2. T1552.007 Container API1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Mattermost