
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3471 is a Denial of Service vulnerability in the Mattermost Desktop App caused by improper handling of invalid URLs in pop-up windows. Affected versions include all releases up to and including 5.4.13.0, versions 6.0.0–6.0.1, and versions 6.1.0–6.1.x (prior to 6.2.0). A malicious server owner can repeatedly crash the application by invoking window.open('javascript:alert()') in a pop-up context. The vulnerability was published on May 18, 2026, with Mattermost Advisory ID MMSA-2026-00618, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-939 (Improper Authorization in Handler for Custom URL Scheme): the Mattermost Desktop App fails to validate or restrict the URL schemes permitted to load in pop-up windows spawned via window.open(). By passing a javascript: URI (e.g., window.open('javascript:alert()')) from a controlled Mattermost server, an attacker can cause the Electron-based desktop client to load an invalid URL in a pop-up, triggering an application crash. Exploitation requires the victim to be connected to a malicious or compromised Mattermost server and to interact with content that triggers the pop-up, making user interaction a prerequisite (GitHub Advisory, Mattermost Security).
Successful exploitation results in a repeated, forced crash of the Mattermost Desktop App, causing a High availability impact with no confidentiality or integrity loss. A malicious server owner can continuously trigger the crash, effectively denying the user access to the Mattermost client for as long as the user remains connected to the malicious server. There is no evidence of data exfiltration or lateral movement potential associated with this vulnerability (GitHub Advisory, Mattermost Security).
window.open('javascript:alert()'), opening a pop-up with an invalid javascript: URL scheme.javascript: URI in a new pop-up window.javascript: URI handling or pop-up window failures.Mattermost.exe on Windows, mattermost on Linux/macOS) in rapid succession without user-initiated closure.Users should upgrade the Mattermost Desktop App to version 6.2.0 or later, which addresses this vulnerability. As a workaround, users should avoid connecting the Desktop App to untrusted or unknown Mattermost server instances. Organizations should restrict which Mattermost servers employees are permitted to connect to via policy or network controls. Patch details are available via the Mattermost security updates page (Mattermost Security, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."