CVE-2026-1628: Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1628?
CVE-2026-1628 has been classified as a medium severity vulnerability.
How do I fix CVE-2026-1628?
To fix CVE-2026-1628, update the Mattermost Desktop App to version 5.13.4 or later.
What versions of Mattermost Desktop App are affected by CVE-2026-1628?
CVE-2026-1628 affects Mattermost Desktop App versions 5.13.3 and earlier.
What impact does CVE-2026-1628 have on users?
CVE-2026-1628 can allow malicious servers to expose preload scripts in the Mattermost app, potentially leading to data theft.
Is there a workaround for CVE-2026-1628?
Currently, there is no known workaround for CVE-2026-1628 other than updating to a patched version.