CVE-2026-3471: Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3471?
CVE-2026-3471 has a medium severity rating as it allows a malicious server owner to crash the Mattermost Desktop App.
How do I fix CVE-2026-3471?
To fix CVE-2026-3471, update the Mattermost Desktop App to version 6.1 or later.
Which versions of the Mattermost Desktop App are affected by CVE-2026-3471?
CVE-2026-3471 affects Mattermost Desktop App versions 6.0.1, 5.4.13.0, and earlier versions.
What exploit is associated with CVE-2026-3471?
CVE-2026-3471 can be exploited by opening a pop-up window with the URL 'javascript:alert()' leading to crashes.
Is CVE-2026-3471 being addressed by the vendor?
Yes, the Mattermost team has acknowledged CVE-2026-3471 and is providing security updates to address the issue.