Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mattermost-desktop(npm) | 0 | 5.11.0 | N/A |
CVSS Metrics