CVE-2026-3471
Mattermost Desktop App vulnerability analysis and mitigation

Overview

CVE-2026-3471 is a Denial of Service vulnerability in the Mattermost Desktop App caused by improper handling of invalid URLs in pop-up windows. Affected versions include all releases up to and including 5.4.13.0, versions 6.0.0–6.0.1, and versions 6.1.0–6.1.x (prior to 6.2.0). A malicious server owner can repeatedly crash the application by invoking window.open('javascript:alert()') in a pop-up context. The vulnerability was published on May 18, 2026, with Mattermost Advisory ID MMSA-2026-00618, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Mattermost Security).

Technical details

The root cause is classified as CWE-939 (Improper Authorization in Handler for Custom URL Scheme): the Mattermost Desktop App fails to validate or restrict the URL schemes permitted to load in pop-up windows spawned via window.open(). By passing a javascript: URI (e.g., window.open('javascript:alert()')) from a controlled Mattermost server, an attacker can cause the Electron-based desktop client to load an invalid URL in a pop-up, triggering an application crash. Exploitation requires the victim to be connected to a malicious or compromised Mattermost server and to interact with content that triggers the pop-up, making user interaction a prerequisite (GitHub Advisory, Mattermost Security).

Impact

Successful exploitation results in a repeated, forced crash of the Mattermost Desktop App, causing a High availability impact with no confidentiality or integrity loss. A malicious server owner can continuously trigger the crash, effectively denying the user access to the Mattermost client for as long as the user remains connected to the malicious server. There is no evidence of data exfiltration or lateral movement potential associated with this vulnerability (GitHub Advisory, Mattermost Security).

Exploitation steps

  1. Set up a malicious Mattermost server: The attacker operates or compromises a Mattermost server instance that target users connect to with the Mattermost Desktop App.
  2. Inject malicious JavaScript trigger: On the server side, craft content (e.g., a message, plugin, or custom integration) that causes the Desktop App to execute window.open('javascript:alert()'), opening a pop-up with an invalid javascript: URL scheme.
  3. Trigger the pop-up on the victim's client: When the victim interacts with the malicious content (e.g., clicks a link or loads a page that auto-triggers the call), the Desktop App attempts to load the javascript: URI in a new pop-up window.
  4. Application crash: The Desktop App fails to handle the invalid URL scheme, causing an unhandled exception and crashing the application. The attacker can repeat this process to persistently deny the user access to the client (GitHub Advisory, Mattermost Security).

Indicators of compromise

  • Logs: Repeated Mattermost Desktop App crash logs or Electron renderer process crash reports, particularly referencing javascript: URI handling or pop-up window failures.
  • Process: Unexpected termination of the Mattermost Desktop App process (Mattermost.exe on Windows, mattermost on Linux/macOS) in rapid succession without user-initiated closure.
  • Network: Desktop App connections to an unfamiliar or untrusted Mattermost server URL prior to crash events.
  • Application Events: OS-level application crash reports (e.g., Windows Event Log Application errors, macOS crash reporter entries) tied to the Mattermost Desktop process around the time of repeated crashes.

Mitigation and workarounds

Users should upgrade the Mattermost Desktop App to version 6.2.0 or later, which addresses this vulnerability. As a workaround, users should avoid connecting the Desktop App to untrusted or unknown Mattermost server instances. Organizations should restrict which Mattermost servers employees are permitted to connect to via policy or network controls. Patch details are available via the Mattermost security updates page (Mattermost Security, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Mattermost Desktop App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6517HIGH7.7
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesJun 15, 2026
CVE-2026-8683MEDIUM6.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesJun 15, 2026
CVE-2026-3471MEDIUM6.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesMay 18, 2026
CVE-2026-1628MEDIUM4.6
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesMar 02, 2026
CVE-2026-4643LOW3.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesMay 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management