CVE-2025-1398

LOW

Mattermost Desktop < 5.11.0 - Untrusted Search Path

Title source: rule
STIX 2.1

Description

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

Scores

CVSS v3 3.3
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-426
Status published
Products (2)
mattermost/mattermost_desktop < 5.11.0
npm/mattermost-desktop 0 - 5.11.0npm
Published Mar 17, 2025
Tracked Since Feb 18, 2026