Impact
Mattermost Desktop App versions up to 6.2.2.0 expose a flaw that does not adequately restrict server-rendered content, allowing content delivered by an external server to access or influence local or private network resources. This vulnerability could enable an attacker who is able to supply or modify such content to read internal data, execute actions on local machines, or otherwise compromise resources within the victim’s network.
Affected Systems
Mattermost Desktop App for all platforms built by Mattermost, specifically any installation running version 6.2.2.0 or earlier. The vendor responsible for remediation is Mattermost.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate potential impact, while the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply malformed server‑rendered content to the victim’s desktop application, which may be feasible in scenarios where a malicious partner or compromised content provider is involved.
OpenCVE Enrichment