← Vulnerability feed

Vulnerability record · CVE-2024-39613 · published 16 September 2024

CVE-2024-39613: Mattermost desktop uncontrolled search path element vulnerability

Mattermost · Mattermost Desktop

Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.

7.8 CVSS 3.1 High EPSS 0.30% · top 79.7% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://mattermost.com/security-updates Vendor Advisory

Track CVE-2024-39613 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-11064Mattermost desktop code injection vulnerabilityAn issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.EPSS 1.3%9.8CVE-2019-20856Mattermost desktop uncontrolled search path element vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.EPSS 1.4%8.8CVE-2019-20861Mattermost desktop vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.EPSS 1.7%7.7CVE-2026-6517Mattermost desktop insufficiently protected credentials vulnerabilityMattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo…EPSS 0.32%7.3CVE-2020-14456Mattermost desktop origin validation error vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, ak…EPSS 0.43%6.5CVE-2026-8075Mattermost desktop vulnerabilityMattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows…EPSS 0.42%6.5CVE-2026-9602Mattermost desktop uncontrolled resource consumption vulnerabilityMattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a mal…EPSS 0.42%6.5CVE-2026-8683Mattermost desktop allocation without limits vulnerabilityMattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows …EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2024-39613), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.