CVE-2017-14586: Atlassian Hipchat

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.

Affected products

  • Atlassian Hipchat: from 4.0, before 4.30 (fixed in 4.30)

Published 2017-11-27. Last modified 2026-06-17.