CVE-2025-55035: Mattermost Desktop

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed.

Affected products

  • Mattermost Mattermost Desktop: before 5.13.1.0 (fixed in 5.13.1.0)

Published 2025-10-16. Last modified 2026-06-17.