Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Desktop App to versions 6.2.0, 6.1.1.0, 5.13.5.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Fri, 05 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Desktop
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Desktop
|
Mon, 18 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 18 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, leading to a denial of service condition at the client level. Mattermost Advisory ID: MMSA-2026-00633 | |
| Title | Calling window.close() from server-side content causes crash in the Mattermost Desktop App | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-05-18T14:36:01.271Z
Reserved: 2026-03-23T11:42:45.791Z
Link: CVE-2026-4643
Updated: 2026-05-18T14:35:55.446Z
Status : Analyzed
Published: 2026-05-18T09:16:23.127
Modified: 2026-06-17T10:56:58.200
Link: CVE-2026-4643
No data.
OpenCVE Enrichment
Updated: 2026-05-18T10:30:23Z