Back

LOW

Calling window.close() from server-side content causes crash in the Mattermost Desktop App

Published May 18, 2026

Description

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, leading to a denial of service condition at the client level. Mattermost Advisory ID: MMSA-2026-00633

Affected products

Remediation

Vendor solution

Update Mattermost Desktop App to versions 6.2.0, 6.1.1.0, 5.13.5.0 or higher.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published May 18, 2026
Updated May 18, 2026
Reserved Mar 23, 2026
CISA Vulnrichment
Updated May 18, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a