Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
{
"cwe_ids": [
"CWE-693"
],
"nvd_published_at": "2024-06-14T09:15:10Z",
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2024-06-17T21:23:17Z"
}