
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8683 is a Denial of Service (DoS) vulnerability in the Mattermost Desktop App that allows a malicious server owner to crash the application by triggering it to open an extremely long URL. Affected versions include Mattermost Desktop App ≤6.1.5 and ≤5.13.0; fixed versions are 6.2.0 and 5.13.6.0. The vulnerability was published on June 15, 2026, with Mattermost Advisory ID MMSA-2026-00652. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) — the Mattermost Desktop App fails to impose any size restrictions when handling URLs passed to window.open(). A malicious server can inject a script that calls window.open() with an extremely large URL string, causing the Electron-based desktop application to attempt resource allocation beyond its capacity and crash. Exploitation requires user interaction in the form of a user connecting to a malicious Mattermost server, and the attacker must control or compromise a Mattermost server instance (GitHub Advisory, Mattermost Security).
Successful exploitation results in a crash of the Mattermost Desktop App on the victim's machine, causing a loss of availability (Denial of Service). There is no impact on confidentiality or data integrity — the vulnerability cannot be used to access, exfiltrate, or modify data. The scope is limited to the affected desktop client; server-side infrastructure and other users are not directly impacted (GitHub Advisory).
window.open() with an extremely long URL string (e.g., a URL of several megabytes or more).window.open(), exhausting resources and causing the application to crash (GitHub Advisory).Mattermost desktop application process without user-initiated action..dmp files) in the application's crash reporting directory following unexpected application termination.Mattermost has released patched versions 6.2.0 and 5.13.6.0 that address this vulnerability; users should upgrade to these or later versions immediately (Mattermost Security, GitHub Advisory). As a temporary workaround if patching is not immediately possible, administrators should restrict users from connecting to untrusted or external Mattermost servers. Organizations should also review and validate the Mattermost security advisory MMSA-2026-00652 for additional guidance.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."