CVE-2025-13321: Mattermost Desktop App logging sensitive information and fails to clear data on server deletion
Mattermost Desktop App versions < 6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
A fix is available for direct download via the Mattermost Desktop repository, but it has not been uploaded to the npm registry at time of publication.
Other sources
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13321?
CVE-2025-13321 has a moderate severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2025-13321?
To fix CVE-2025-13321, upgrade Mattermost Desktop App to version 6.0.0 or later.
What information is exposed in CVE-2025-13321?
CVE-2025-13321 may expose sensitive user information stored in application logs.
Who is affected by CVE-2025-13321?
Users of Mattermost Desktop App versions prior to 6.0.0 are affected by CVE-2025-13321.
Can CVE-2025-13321 be exploited remotely?
CVE-2025-13321 cannot be exploited remotely; an attacker must have access to the user’s system.