VDB
Sign up
LOW3.3

GHSA-xmvv-w44w-j8wx

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

Quick fix

GHSA-xmvv-w44w-j8wx — mattermost-desktop: upgrade to the fixed version with the command below.

npm install mattermost-desktop@5.11.0

Details

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mattermost-desktop
Introduced in: 0Fixed in: 5.11.0
Fixnpm install mattermost-desktop@5.11.0

References