Denial of Service Vulnerability in Mattermost Desktop App
CVE-2026-8683

6.5MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
15 June 2026

What is CVE-2026-8683?

The Mattermost Desktop App versions up to 6.1 and 5.5.13.0 are susceptible to a denial of service due to improper handling of excessively long URLs. This vulnerability allows malicious attackers to exploit the situation by crafting a URL that, when invoked, causes the application to crash. The issue arises when the app attempts to process extremely long URLs, particularly when a script invokes a window.open command. Users are advised to update to the latest version to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Mattermost 0 <= 5.5.13

Mattermost 6.2.0

Mattermost 5.13.6.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

game0v3r
.