Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.
Vulnerability Description
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
从非可信控制范围包含功能例程
Vulnerability Title
Mattermost Desktop App 安全漏洞
Vulnerability Description
Mattermost Desktop App是美国Mattermost公司的一款消息传递桌面版应用程序。 Mattermost Desktop App 5.13.3及之前版本存在安全漏洞,该漏洞源于未附加限制导航到外部站点的监听器,可能导致恶意服务器向不受信任的服务器暴露预加载脚本功能。
CVSS Information
N/A
Vulnerability Type
N/A