Description
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of those headers. Mattermost Advisory ID: MMSA-2026-00668
Published: 2026-07-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost Desktop App versions up to 6.2, 5.5.13, and 6.0.2.0 contain a flaw where the application fails to properly validate the presence of required headers when rendering a markdown image. This oversight allows an attacker to embed a malicious link containing an image missing one of those headers, causing the target user's desktop client to crash. The weakness is a null‑reference error and results in a denial of service that impacts the availability of the desktop application for channel participants.

Affected Systems

The affected systems are Mattermost Desktop App instances running any of the following versions: 6.2 or earlier, 5.5.13, or 6.0.2.0. Users of Mattermost who rely on the desktop client for communication are therefore at risk.

Risk and Exploitability

Based on the CVSS v3.1 score of 6.5, the vulnerability presents a moderate severity impact. The EPSS score indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the posting of a malicious markdown image by any user with access to a channel; the victim receives a crash when the image is rendered.

Generated by OpenCVE AI on July 31, 2026 at 00:31 UTC.

Remediation

Vendor Solution

Update Mattermost Desktop App to versions 6.3.0, 5.13.6.0, 6.2.1.0 or higher.


OpenCVE Recommended Actions

  • Update Mattermost Desktop App to version 6.3.0, 5.13.6.0, 6.2.1.0 or any newer release, as supplied by the official Mattermost security advisory.
  • If an immediate upgrade is not possible, limit exposure by avoiding clicking or loading images from untrusted or newly posted links in channels until the software is patched.
  • Consider using the Mattermost web or mobile client as a temporary workaround until the desktop client is updated.

Generated by OpenCVE AI on July 31, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Fri, 17 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of those headers. Mattermost Advisory ID: MMSA-2026-00668
Title Posting a malicious markdown image crashes the Mattermost Desktop App
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-17T12:53:59.567Z

Reserved: 2026-05-07T10:57:31.807Z

Link: CVE-2026-8075

cve-icon Vulnrichment

Updated: 2026-07-17T12:53:56.283Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:45:05Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions