{"id":"CVE-2026-3471","summary":"Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App","details":"Mattermost Desktop App versions \u003c=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618","modified":"2026-08-12T03:51:22.865783713Z","published":"2026-05-18T08:45:44.576Z","database_specific":{"cwe_ids":["CWE-939"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3471.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"last_affected":"6.0.1"},{"last_affected":"5.4.13"}]}],"cna_assigner":"Mattermost"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3471.json"},{"type":"ADVISORY","url":"https://mattermost.com/security-updates"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3471"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mattermost/desktop","events":[{"introduced":"dd2c7c4b66d726250980171a113a8764ab8f8777"},{"last_affected":"0836d9fdbec86e1fc68b09f4274a35526c043130"},{"introduced":"183deb7776c34bd0db35d61071e3b1c9311eea64"},{"fixed":"200c274b361a2dcb7d7e8208adc44bdcd4645616"}],"database_specific":{"cpe":"cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.0.0"},{"last_affected":"6.0.1"},{"introduced":"6.1.0"},{"fixed":"6.2.0"}],"source":"CPE_RANGE"}}],"versions":["v6.0.1-mas.1","v6.0.1","v6.0.1-rc.2","v6.0.1-rc.1","v6.0.0-mas.1","v6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3471.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}