Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HDefault status
unaffected
Any version
affected
6.2.0
unaffected
5.13.6.0
unaffected
Description
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-00652
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
Any version
6.2.0
5.13.6.0
Credits
game0v3r
References
mattermost.com/security-updates (MMSA-2026-00652)