CVE-2025-1398: Mattermost Desktop

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

Affected products

  • Mattermost Mattermost Desktop: before 5.11.0 (fixed in 5.11.0)

Published 2025-03-17. Last modified 2026-06-17.