Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
Advisories

No advisories yet.

Fixes

Solution

Update Mattermost Desktop App to versions 5.13.1 or higher.


Workaround

No workaround given by the vendor.

References
History

Wed, 29 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Desktop
CPEs cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Desktop

Mon, 20 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Tue, 14 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
Title Mattermost Desktop App crashes when clicking on malformed external URL
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-10-14T14:28:52.930Z

Reserved: 2025-09-11T18:33:39.540Z

Link: CVE-2025-58084

cve-icon Vulnrichment

Updated: 2025-10-14T14:28:49.334Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-13T20:15:33.937

Modified: 2025-10-29T13:34:07.720

Link: CVE-2025-58084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-20T16:13:27Z