Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-12-17 19:16
Updated : 2025-12-18 19:41
NVD link : CVE-2025-13321
Mitre link : CVE-2025-13321
CVE.ORG link : CVE-2025-13321
JSON object : View
Products Affected
mattermost
- mattermost_desktop
CWE
CWE-532
Insertion of Sensitive Information into Log File
