VendorsMattermostmattermost_desktopany version
Vulnerabilities

Mattermost Desktop any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

31CVEs
CVE-2019-20856
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
Published 2020-06-19 · Modified
9.8EPSS 0.014
CVE-2016-11064
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
Published 2020-06-19 · Modified
9.8EPSS 0.013
CVE-2019-20861
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.
Published 2020-06-19 · Modified
8.8EPSS 0.017
CVE-2024-39613
RCE in desktop app in Windows by local attacker
Published 2024-09-16 · Analyzed
7.8EPSS 0.003
CVE-2026-6517
Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed
Published 2026-06-15 · Analyzed
7.7EPSS 0.002
CVE-2026-1046
Arbitrary application execution via unvalidated server-controlled URLs in Help menu
Published 2026-02-16 · Analyzed
7.6EPSS 0.002
CVE-2020-14456
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
Published 2020-06-19 · Modified
7.5EPSS 0.004
CVE-2020-14455
An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.
Published 2020-06-19 · Modified
6.5EPSS 0.012
CVE-2026-9602
Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods
Published 2026-07-17 · Analyzed
6.5EPSS 0.004
CVE-2026-8075
Posting a malicious markdown image crashes the Mattermost Desktop App
Published 2026-07-17 · Analyzed
6.5EPSS 0.004
CVE-2025-58084
Mattermost Desktop App crashes when clicking on malformed external URL
Published 2025-10-13 · Analyzed
6.5EPSS 0.003
CVE-2024-45835
Insufficient Electron Fuses Configuration
Published 2024-09-16 · Analyzed
6.5EPSS 0.002
CVE-2026-8683
Overly long URLs crash the Mattermost Desktop App
Published 2026-06-15 · Analyzed
6.5EPSS 0.002
CVE-2026-3471
Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App
Published 2026-05-18 · Analyzed
6.5EPSS 0.002
CVE-2020-14454
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2025-55035
Mattermost Desktop DoS when user has basic authentication server configured
Published 2025-10-16 · Analyzed
6.1EPSS 0.003
CVE-2024-37182
Lack of permissions prompting when opening external URLs
Published 2024-06-14 · Modified
6.1EPSS 0.003
CVE-2023-5339
Mattermost Desktop logs all keystrokes during initial run after fresh installation 
Published 2023-10-17 · Modified
5.5EPSS 0.001
CVE-2023-2000
Unrestricted navigation due to unvalidated mattermost server redirection
Published 2023-05-02 · Modified
5.4EPSS 0.004
CVE-2018-21265
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2023-5876
Regex DoS from a malicious server enrolled in Desktop
Published 2023-11-02 · Modified
5.3EPSS 0.005
CVE-2023-5875
Lack of Hardening against media exploitation from a remote origin
Published 2023-11-02 · Modified
5.3EPSS 0.003
CVE-2024-39772
Silent Desktop Screenshot Capture
Published 2024-09-16 · Analyzed
5.3EPSS 0.003
CVE-2026-1628
Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.
Published 2026-03-02 · Analyzed
4.6EPSS 0.001
CVE-2025-13326
Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store
Published 2025-12-17 · Analyzed
3.9EPSS 0.001
CVE-2024-36287
Bypass of TCC restrictions on macOS
Published 2024-06-14 · Modified
3.8EPSS 0.002
CVE-2026-75587
Plaintext pre-auth secret exposure via Desktop App diagnostics report
Published 2026-08-17 · Analyzed
3.6EPSS 0.001
CVE-2026-4643
Calling window.close() from server-side content causes crash in the Mattermost Desktop App
Published 2026-05-18 · Analyzed
3.5EPSS 0.002
CVE-2023-5920
Lack Of Secure Keyboard Entry Protection in MacOS Desktop
Published 2023-11-02 · Modified
3.3EPSS 0.002
CVE-2025-1398
macOS TCC Bypass via Code Injection
Published 2025-03-17 · Analyzed
3.3EPSS 0.002
CVE-2025-13321
Mattermost Desktop App logging sensitive information and fails to clear data on server deletion
Published 2025-12-17 · Analyzed
3.3EPSS 0.001