CVE-2025-13326: Mattermost Desktop

Low severity, CVSS 3.9. EPSS: 0.1% chance of exploitation in the next 30 days.

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.

Affected products

  • Mattermost Mattermost Desktop: before 6.0.0 (fixed in 6.0.0)

Published 2025-12-17. Last modified 2026-06-17.