Junglewise Threat Intelligence

CVE-2026-75025: Mattermost Desktop App content restriction bypass

CVE-2026-75025 · Severity: medium · CVSS 4.7 · Published 2026-09-16

Executive brief

Mattermost Desktop App is a communication and collaboration tool used by teams to share messages and files. In versions 6.2 and earlier, the application failed to properly isolate server-rendered content, allowing it to access local network resources and potentially exposing sensitive information on users' computers. This could be exploited by a malicious Mattermost server to access files or network services without the user's knowledge.

Technical details

The vulnerability is a content restriction bypass in Mattermost Desktop App versions 6.2 and earlier. The application did not sufficiently restrict server-rendered content from accessing local or private network resources, violating security sandboxing principles. An attacker controlling or compromising a Mattermost server could craft malicious content that, when rendered by the desktop client, accesses local files, internal network services, or performs unauthorized operations on the user's machine. Network-accessible attack vector, no authentication required from the attacker perspective (the user must be connected to a compromised server). The issue was fixed in version 6.2.2.0.

Affected products

  • Mattermost Desktop App <=6.2, fixed in 6.2.2.0

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fixed in version 6.2.2.0

References

Related threats