VYPR
Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026

Posting a malicious markdown image crashes the Mattermost Desktop App

CVE-2026-8075

Description

Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of those headers. Mattermost Advisory ID: MMSA-2026-00668

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.