Mattermost
Mattermost Desktop: vulnerabilidades y CVE
Mattermost Desktop tiene 31 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses13
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75587 | Baja (3.3) | 0.13% | — | 17 ago 2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the… |
| CVE-2026-9602 | Media (6.5) | 0.42% | — | 17 jul 2026 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing… |
| CVE-2026-8075 | Media (6.5) | 0.42% | — | 17 jul 2026 | Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a… |
| CVE-2026-8683 | Media (6.5) | 0.36% | — | 15 jun 2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a… |
| CVE-2026-6517 | Alta (7.7) | 0.32% | — | 15 jun 2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image… |
| CVE-2026-4643 | Baja (3.5) | 0.29% | — | 18 may 2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash… |
| CVE-2026-3471 | Media (6.5) | 0.33% | — | 18 may 2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application… |
| CVE-2026-1628 | Media (4.6) | 0.14% | — | 2 mar 2026 | Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted… |
| CVE-2026-1046 | Media (6.5) | 0.24% | — | 16 feb 2026 | Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in… |
| CVE-2025-13326 | Baja (3.9) | 0.11% | — | 17 dic 2025 | Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a… |
| CVE-2025-13321 | Baja (3.3) | 0.12% | — | 17 dic 2025 | Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially… |
| CVE-2025-55035 | Media (6.1) | 0.32% | — | 16 oct 2025 | Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that… |
| CVE-2025-58084 | Media (6.5) | 0.30% | — | 13 oct 2025 | Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user… |
| CVE-2025-1398 | Baja (3.3) | 0.17% | — | 17 mar 2025 | Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection. |
| CVE-2024-45835 | Media (6.5) | 0.21% | — | 16 sept 2024 | Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access. |
| CVE-2024-39772 | Media (5.3) | 0.31% | — | 16 sept 2024 | Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs. |
| CVE-2024-39613 | Alta (7.8) | 0.30% | — | 16 sept 2024 | Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to… |
| CVE-2024-37182 | Media (6.1) | 0.30% | — | 14 jun 2024 | Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's… |
| CVE-2024-36287 | Baja (3.3) | 0.19% | — | 14 jun 2024 | Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS. |
| CVE-2023-5920 | Baja (3.3) | 0.19% | — | 2 nov 2023 | Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input. |
| CVE-2023-5876 | Media (5.3) | 0.49% | — | 2 nov 2023 | Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service. |
| CVE-2023-5875 | Media (5.3) | 0.33% | — | 2 nov 2023 | Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server |
| CVE-2023-5339 | Media (5.5) | 0.14% | — | 17 oct 2023 | Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. |
| CVE-2023-2000 | Media (5.4) | 0.36% | — | 2 may 2023 | Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website |
| CVE-2016-11064 | Crítica (9.8) | 1.3% | — | 19 jun 2020 | An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection. |
| CVE-2018-21265 | Media (5.3) | 0.77% | — | 19 jun 2020 | An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications). |
| CVE-2019-20861 | Alta (8.8) | 1.7% | — | 19 jun 2020 | An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link. |
| CVE-2019-20856 | Crítica (9.8) | 1.4% | — | 19 jun 2020 | An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection. |
| CVE-2020-14456 | Alta (7.3) | 0.43% | — | 19 jun 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006. |
| CVE-2020-14455 | Media (6.5) | 1.2% | — | 19 jun 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.