Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
Advisories

No advisories yet.

Fixes

Solution

Update Mattermost Desktop App to versions 5.13.1 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 13 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
Title Mattermost Desktop App crashes when clicking on malformed external URL
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-10-13T19:57:23.997Z

Reserved: 2025-09-11T18:33:39.540Z

Link: CVE-2025-58084

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-13T20:15:33.937

Modified: 2025-10-13T20:15:33.937

Link: CVE-2025-58084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.