CVE-2026-3472: Markdown image rendering bypass in AI bot tool result posts in Mattermost
Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image syntax into tool result content rendered by a victim's client.. Mattermost Advisory ID: MMSA-2026-00619
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.19 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.4 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3472?
The severity of CVE-2026-3472 is rated low with a score of 3.5.
How do I fix CVE-2026-3472?
To fix CVE-2026-3472, upgrade Mattermost to version 10.11.19, 11.6.4, or 11.5.7 or later.
What does CVE-2026-3472 exploit?
CVE-2026-3472 exploits the improper application of markdown image rendering restrictions in AI bot tool result posts.
Who is affected by CVE-2026-3472?
CVE-2026-3472 affects Mattermost versions 10.11.x up to 10.11.18, 11.6.x up to 11.6.3, and 11.5.x up to 11.5.6.
What can an attacker do with CVE-2026-3472?
An authenticated attacker can exfiltrate data to an attacker-controlled server by injecting markdown image syntax.