mattermost-desktop
npm6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mattermost-desktoppage 1 of 1
- CVE-2024-36287LOWCVSS 3.8EG 3.8✓ Fixed in 5.8.02024-06-14
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
- CVE-2024-37182MEDIUMCVSS 4.7EG 4.7✓ Fixed in 5.8.02024-06-14
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI…
- CVE-2024-39613MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.9.02024-09-16
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code e…
- CVE-2024-39772LOWCVSS 3.7EG 3.7✓ Fixed in 5.9.02024-09-16
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
- CVE-2024-45835LOWCVSS 2.5EG 2.5✓ Fixed in 5.9.02024-09-16
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
- CVE-2025-1398LOWCVSS 3.3EG 3.3✓ Fixed in 5.11.02025-03-17
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
Check whether mattermost-desktop is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mattermost-desktop CVEs against the assets you own.
Start Free Scan →