Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2717 Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
Github GHSA Github GHSA GHSA-5777-rcjj-9p22 Mattermost Desktop App fails to safeguard screen capture functionality
Fixes

Solution

Update Mattermost Desktop App to versions 5.9.0 or higher.


Workaround

No workaround given by the vendor.

References
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0009}

epss

{'score': 0.00106}


Fri, 01 Nov 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Desktop
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server
Mattermost mattermost Desktop

Tue, 17 Sep 2024 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Mon, 16 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
Title Silent Desktop Screenshot Capture
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-16T14:42:19.953Z

Reserved: 2024-09-11T15:59:49.540Z

Link: CVE-2024-39772

cve-icon Vulnrichment

Updated: 2024-09-16T14:41:36.842Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-16T15:15:16.350

Modified: 2024-11-01T14:20:22.217

Link: CVE-2024-39772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.