Security researcher David Wells from Tenable discovered a critical flaw in version 3.3.7 of the Slack desktop app that could be exploited to steal and manipulate a targeted users downloaded files. The issue is classified as a download hijacking vulnerability that can be triggered by tricking a user into clicking on a specially crafted link pasted into a Slack channel. Slack awarded $500 the researcher under its bug bounty program under its $500 bounty program. The flaw has been classified as medium severity because it required user interaction.”]
Source: https://securityaffairs.co/wordpress/85725/hacking/slack-flaw-2.html

