Description
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost Advisory ID: MMSA-2026-00678
CVSS 6.5EPSS 0.24%Risk 0.66
View source- Published
- 2026-07-17 11:17:15
- Affected versions
- <=6.2
- Type
- Critical software
- Last modified
- 2026-07-30 14:38:53
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H