CVE-2026-3471
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.18%
- CWE
- CWE-939
- Published
- 2026-05-18
- Last modified
- 2026-05-18
Affected products
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
Weakness type
Related vulnerabilities
- CVE-2026-73335 — Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL...
- CVE-2026-59717 — Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
- CVE-2026-12190 — Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
- CVE-2026-12189 — Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
- CVE-2026-53408 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for...
- CVE-2026-53407 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for...
- CVE-2026-12065 — Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
- CVE-2026-6445 — A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose...