CVE-2026-8075: Posting a malicious markdown image crashes the Mattermost Desktop App
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of those headers. Mattermost Advisory ID: MMSA-2026-00668
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 6.3.0 - Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 5.13.6.0 - Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 6.2.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8075?
The severity of CVE-2026-8075 is classified as medium with a score of 6.5.
How do I fix CVE-2026-8075?
To fix CVE-2026-8075, you should update the Mattermost Desktop App to the latest version that addresses this vulnerability.
What versions of Mattermost Desktop App are affected by CVE-2026-8075?
Mattermost Desktop App versions up to and including 6.2, 5.5.13, and 6.0.2.0 are affected by CVE-2026-8075.
What type of attack is possible due to CVE-2026-8075?
CVE-2026-8075 allows an attacker to crash the Mattermost Desktop App of another user by posting a malicious markdown image link.
Is user interaction required for CVE-2026-8075 to be exploited?
Yes, user interaction is required as the attack relies on a user posting a malicious link in the Mattermost channel.