CVE-2025-13321

Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-17 19:16

Updated : 2025-12-18 19:41


NVD link : CVE-2025-13321

Mitre link : CVE-2025-13321

CVE.ORG link : CVE-2025-13321


JSON object : View

Products Affected

mattermost

  • mattermost_desktop
CWE
CWE-532

Insertion of Sensitive Information into Log File