CVE 3.3 LOW

Mattermost Desktop App logging sensitive information and fails to clear data on server deletion_CVE-2025-13321

3.3 / 10
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.

Basic Information

ID CVE-2025-13321
Source Mattermost
Published Dec 17, 2025 at 18:14
Modified Dec 17, 2025 at 19:29

Affected Product

Vendor Mattermost
Product Mattermost
Affected Versions Mattermost Mattermost 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.