Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HMattermost Desktop
APPMattermost≤ 5.4.13.06.0.0 – 6.0.16.1.0 – 6.2.0 (excl.)
Related vulnerabilities
Mattermost Desktop: code injection umożliwiający zdalne wykonanie kodu
Mattermost Desktop (macOS) — podatność na dylib injection
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Matt...
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code ...
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during ac...