Impact
Mattermost Desktop App versions up to 6.2, 5.5.13, and 6.0.2.0 contain a flaw where the application fails to properly validate the presence of required headers when rendering a markdown image. This oversight allows an attacker to embed a malicious link containing an image missing one of those headers, causing the target user's desktop client to crash. The weakness is a null‑reference error and results in a denial of service that impacts the availability of the desktop application for channel participants.
Affected Systems
The affected systems are Mattermost Desktop App instances running any of the following versions: 6.2 or earlier, 5.5.13, or 6.0.2.0. Users of Mattermost who rely on the desktop client for communication are therefore at risk.
Risk and Exploitability
Based on the CVSS v3.1 score of 6.5, the vulnerability presents a moderate severity impact. The EPSS score indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the posting of a malicious markdown image by any user with access to a channel; the victim receives a crash when the image is rendered.
OpenCVE Enrichment