Mattermost Desktop App
cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*
- <= 6.0
- <= 6.2.0
- <= 5.2.13.0
A vulnerability exists in the Mattermost Desktop App in versions through 6.2.0 and 5.2.13.0, where the application fails to properly validate help links. This flaw enables a malicious Mattermost server to execute arbitrary executables on a user's system. The issue arises when a user clicks on specific items in the Help menu.
Exploitation of this vulnerability allows for the execution of arbitrary executables on the user's system, potentially leading to unauthorized actions or changes.
Users can upgrade to Mattermost Desktop App version 6.4.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.