CVE-2026-4643 Details
Description
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, leading to a denial of service condition at the client level. Mattermost Advisory ID: MMSA-2026-00633
A denial-of-service vulnerability has been identified in the Mattermost Desktop App, affecting versions 6.1, 6.0.1, and 5.4.13.0. The issue arises because the application fails to properly manage server-rendered content, allowing a malicious server or plugin to close an underlying application view. This is achieved by invoking 'window.close()' in the renderer context, which crashes the desktop client and disrupts the user's experience.
Users are advised to update to the latest version of the Mattermost Desktop App. Details on the security update will be posted on the Mattermost Security Updates page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mattermost.com/security-updates | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mattermost mattermost desktop | <= 5.4.13.0 >= 6.0.0, <= 6.0.1 >= 6.1.0, < 6.2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| May 18, 2026 | New CVE Received | [email protected] |