
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1628 is a navigation restriction bypass vulnerability in the Mattermost Desktop App (versions ≤5.13.3) that allows a malicious server to expose preload script functionality to untrusted external servers. The flaw arises because the application fails to attach listeners that restrict navigation to external sites within the app. When a user opens an external link from a Mattermost server, the preload script — which has elevated privileges within the Electron-based app — can be exposed to untrusted third-party sites. It was published on March 2, 2026, and carries a CVSS v3.1 base score of 4.6 (Medium), tracked under Mattermost Advisory ID MMSA-2026-00596 (Red Hat CVE, Mattermost Security).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere). The Mattermost Desktop App, built on Electron, uses preload scripts that bridge privileged Node.js/Electron APIs to the renderer process. Because the app does not properly attach navigation listeners to block or sandbox external URLs, a malicious Mattermost server can craft links that, when opened by a user, cause the app to navigate to an external site while retaining access to the preload script context. This effectively grants the untrusted external site access to privileged application functionality that should be restricted to trusted Mattermost origins. Exploitation requires the attacker to control or compromise a Mattermost server and requires user interaction (clicking a link) (Red Hat CVE, Mattermost Security).
Successful exploitation can result in low-level confidentiality and integrity impacts: an untrusted external site gaining access to the Mattermost Desktop App's preload script functionality could read sensitive application data or modify application behavior. Availability is not directly impacted. The attack is constrained to users who click malicious links distributed by a compromised or malicious Mattermost server, limiting the blast radius to individual user sessions rather than enabling broad lateral movement (Red Hat CVE).
Mattermost has released a patch in Desktop App version 5.13.4, which addresses this vulnerability by properly attaching navigation listeners to restrict external site navigation. All users running Mattermost Desktop App version 5.13.3 or earlier should upgrade to 5.13.4 or later immediately. As a temporary workaround, users should avoid clicking external links from untrusted or suspicious Mattermost servers, and administrators should monitor for unusual link distributions or suspicious server activity (Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."