Mattermost

Mattermost Desktop

31 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 17.08.2026 22:09:49
  • Zuletzt bearbeitet 19.08.2026 15:53:15

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret confi...

  • EPSS 0.24%
  • Veröffentlicht 17.07.2026 10:05:06
  • Zuletzt bearbeitet 30.07.2026 14:44:35

Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded ...

  • EPSS 0.24%
  • Veröffentlicht 17.07.2026 10:03:26
  • Zuletzt bearbeitet 30.07.2026 14:38:53

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a mal...

  • EPSS 0.2%
  • Veröffentlicht 15.06.2026 14:06:21
  • Zuletzt bearbeitet 16.06.2026 17:18:55

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a ver...

  • EPSS 0.19%
  • Veröffentlicht 15.06.2026 13:55:25
  • Zuletzt bearbeitet 16.06.2026 16:54:47

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other u...

  • EPSS 0.18%
  • Veröffentlicht 18.05.2026 08:45:44
  • Zuletzt bearbeitet 05.06.2026 17:43:51

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javas...

  • EPSS 0.17%
  • Veröffentlicht 18.05.2026 08:43:34
  • Zuletzt bearbeitet 05.06.2026 17:44:47

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking ...

  • EPSS 0.14%
  • Veröffentlicht 02.03.2026 13:24:21
  • Zuletzt bearbeitet 05.03.2026 16:07:40

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an...

Medienbericht
  • EPSS 0.24%
  • Veröffentlicht 16.02.2026 12:10:38
  • Zuletzt bearbeitet 23.03.2026 17:27:17

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisor...

  • EPSS 0.11%
  • Veröffentlicht 17.12.2025 18:14:14
  • Zuletzt bearbeitet 18.12.2025 19:47:06

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.