Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed.
Advisories

No advisories yet.

Fixes

Solution

Update Mattermost Desktop App to versions 5.13.1 or higher.


Workaround

No workaround given by the vendor.

References
History

Thu, 16 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed.
Title Mattermost Desktop DoS when user has basic authentication server configured
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-10-16T16:28:05.951Z

Reserved: 2025-09-11T18:33:39.530Z

Link: CVE-2025-55035

cve-icon Vulnrichment

Updated: 2025-10-16T16:27:51.175Z

cve-icon NVD

Status : Received

Published: 2025-10-16T16:15:38.403

Modified: 2025-10-16T16:15:38.403

Link: CVE-2025-55035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.