Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
Advisories

No advisories yet.

Fixes

Solution

Update Mattermost Desktop App to versions 5.13.1 or higher.


Workaround

No workaround given by the vendor.

References
History

Wed, 29 Oct 2025 22:45:00 +0900

Type Values Removed Values Added
First Time appeared Mattermost mattermost Desktop
CPEs cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Desktop

Tue, 21 Oct 2025 01:15:00 +0900

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Wed, 15 Oct 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Oct 2025 05:15:00 +0900

Type Values Removed Values Added
Description Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
Title Mattermost Desktop App crashes when clicking on malformed external URL
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-10-14T14:28:52.930Z

Reserved: 2025-09-11T18:33:39.540Z

Link: CVE-2025-58084

cve-icon Vulnrichment

Updated: 2025-10-14T14:28:49.334Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-13T20:15:33.937

Modified: 2025-10-29T13:34:07.720

Link: CVE-2025-58084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-21T01:13:27Z

Weaknesses