Vulnerability in Mattermost Desktop App Allows Remote Crash
CVE-2026-3471
6.5MEDIUM
What is CVE-2026-3471?
The Mattermost Desktop App is susceptible to a flaw that permits the loading of invalid URLs within a pop-up window. This weakness can be exploited by malicious actors to crash the application by invoking a specific JavaScript command. The impacted versions include 6.1, 6.0.1, and 5.4.13.0, which underscores the importance of addressing this issue to maintain application stability and security against potential attacks.
Affected Version(s)
Mattermost 0 <= 6.0.1
Mattermost 0 <= 5.4.13
Mattermost 6.2.0