Impact
Mattermost Desktop App versions up to 6.2.2.0 do not validate the URL scheme when determining whether a target URL is internal to the connected server. This flaw allows an attacker positioned on the same network to craft a link that uses a downgraded URL scheme, causing the client to load a plugin popout window over an insecure connection. The result is that a malicious plugin could be loaded without the user’s knowledge, potentially exposing sensitive data or enabling further compromise.
Affected Systems
The vulnerability affects the Mattermost Desktop App from the Mattermost vendor. All releases with a version number of 6.2.2.0 or earlier are impacted; newer releases beginning with 6.2.3.0 or 6.3.0 include the fix.
Risk and Exploitability
The CVSS score of 2.6 indicates low overall severity, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker who can supply a malicious link to a victim via the network, suggesting a network‑based attack vector. While the potential damage is limited, the flaw allows the attacker to force the application to use an insecure connection to load a plugin, which could lead to further exploitation if a malicious plugin is installed.
OpenCVE Enrichment