CVE-2026-26233 PUBLISHED CVSS 4.300000190734863 MEDIUM

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595

Risk Scores

CVSS v3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
mattermostmattermost_server10.11.0, 11.4.0, 10.11.0
github.commattermost/mattermost-server11.3.0-rc1, 11.2.0-rc1, 10.11.0-rc1
MattermostMattermost11.4.0, 11.2.0, 10.11.0

Timeline

References

Open in Interactive Console →