
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4643 is a denial-of-service vulnerability in the Mattermost Desktop App that allows a malicious server or plugin to crash the desktop client by invoking window.close() in the renderer context. It affects Mattermost Desktop App versions up to and including 5.4.13.0, versions 6.0.0–6.0.1, and versions 6.1.0 up to (excluding) 6.2.0. The vulnerability was disclosed on May 18, 2026, with initial analysis completed by NIST on June 5, 2026. It carries a CVSS v3.1 base score of 3.5 (Low), assigned by Mattermost, Inc. (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions): the Mattermost Desktop App fails to prevent server-rendered content in the Electron renderer context from invoking window.close(), which closes the underlying application view. Because the app does not validate or restrict this browser API call from untrusted server-side or plugin-supplied content, a malicious Mattermost server or a compromised/malicious plugin can trigger the closure of the application window, effectively crashing the client. Exploitation requires network access, low privileges (an authenticated user account), and user interaction (the user must be connected to the malicious server) (GitHub Advisory, Mattermost Security).
Successful exploitation results in a denial-of-service condition at the client level — the Mattermost Desktop App crashes for the affected user. There is no impact on confidentiality or integrity; only availability is affected (rated Low in scope). The impact is limited to individual desktop clients connecting to a malicious or compromised server, with no evidence of lateral movement potential or data exposure (GitHub Advisory, Mattermost Security).
window.close() call: The malicious server or plugin delivers content to the desktop client's Electron renderer that includes or triggers a window.close() JavaScript call.window.close() invocation or abrupt view closure.Users should update the Mattermost Desktop App to version 6.2.0 or later, which addresses this vulnerability. As a workaround, organizations should restrict plugin installation to trusted, vetted sources only and audit any third-party plugins for malicious code that could invoke window.close(). Users should also avoid connecting to untrusted or unknown Mattermost servers (Mattermost Security, GitHub Advisory).
The vulnerability received limited public attention given its low severity rating. A brief mention was noted on Bluesky via an automated CVE tracking account, and standard aggregator sites (Vulners, VulDB, CVEFeed) indexed the advisory shortly after disclosure. No significant researcher commentary or media coverage has been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."