CVE-2025-13321

M

attermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.

References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*

History

18 Dec 2025, 19:41

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 19:16

Updated : 2025-12-18 19:41


NVD link : CVE-2025-13321

Mitre link : CVE-2025-13321

CVE.ORG link : CVE-2025-13321


JSON object : View

Products Affected
CWE
CWE-532

Insertion of Sensitive Information into Log File