Impact
Mattermost Desktop App does not validate payloads received from the Web App via IPC, allowing an adversary that controls the backing Mattermost server to send malformed data that crashes the desktop client. This failure of input validation (CWE‑400) results in a denial‑of‑service condition where the application terminates unexpectedly, disrupting user workflow and potentially causing data loss. The vulnerability does not expose any data or provide code execution, but it can be leveraged to degrade availability for users on the affected installations.
Affected Systems
Mattermost Desktop App, versions 6.2 and earlier, 6.0.2, and 5.6.13.0 and older, as identified by the Mattermost CNA. Users of these releases should verify the installed version and plan to upgrade to 6.3.0, 6.2.1.0, 5.13.7.0 or later.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation campaigns. The likely attack vector requires an attacker to be in control of a Mattermost server that serves the target desktop client, exploiting the IPC channel over the local network or user’s machine. Since no privilege escalation is required, any user connected to a malicious server could experience the crash, but the impact remains limited to the desktop application rather than system compromise.
OpenCVE Enrichment