Executive brief
Mattermost Desktop App is a communication and collaboration tool used by teams to share messages and files. In versions 6.2 and earlier, the application failed to properly isolate server-rendered content, allowing it to access local network resources and potentially exposing sensitive information on users' computers. This could be exploited by a malicious Mattermost server to access files or network services without the user's knowledge.
Technical details
The vulnerability is a content restriction bypass in Mattermost Desktop App versions 6.2 and earlier. The application did not sufficiently restrict server-rendered content from accessing local or private network resources, violating security sandboxing principles. An attacker controlling or compromising a Mattermost server could craft malicious content that, when rendered by the desktop client, accesses local files, internal network services, or performs unauthorized operations on the user's machine. Network-accessible attack vector, no authentication required from the attacker perspective (the user must be connected to a compromised server). The issue was fixed in version 6.2.2.0.
Affected products
- Mattermost Desktop App <=6.2, fixed in 6.2.2.0
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 6.2.2.0