Description
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618
Problem types
CWE-939: Improper Authorization in Handler for Custom URL Scheme
Product status
Any version
Any version
6.2.0
6.1.1.0
5.13.5.0
Credits
game0v3r
References
mattermost.com/security-updates (MMSA-2026-00618)