Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Desktop App to versions 6.2.0, 6.1.1.0, 5.13.5.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Fri, 05 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Desktop
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Desktop
|
Mon, 18 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 18 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618 | |
| Title | Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App | |
| Weaknesses | CWE-939 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-05-18T14:35:23.933Z
Reserved: 2026-03-03T10:41:41.370Z
Link: CVE-2026-3471
Updated: 2026-05-18T14:34:54.906Z
Status : Analyzed
Published: 2026-05-18T09:16:22.847
Modified: 2026-06-17T10:43:38.350
Link: CVE-2026-3471
No data.
OpenCVE Enrichment
Updated: 2026-05-18T10:30:23Z