CVE-2026-75025: Mattermost Desktop local network access from server-rendered content
Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory ID: MMSA-2026-00698
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 6.3.0 - Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 6.2.3.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Mattermost Desktop App versions up to and including 6.2.2.0 are affected. Exploitation requires a user to interact with server-rendered content in the desktop application.
What access does an attacker need to exploit it?
The vector is network-based and requires no privileges, but user interaction is required. The issue involves server-rendered content accessing local or private network resources.
What should be done to remediate the issue?
Update Mattermost Desktop App to a version newer than 6.2.2.0, where the restriction on server-rendered content accessing local and private network resources has been fixed.