CVE-2026-27659 PUBLISHED CVSS 4.599999904632568 MEDIUM

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595

Risk Scores

CVSS v3.1
4.599999904632568
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
MattermostMattermost10.11.12, 11.4.0, 11.3.0
mattermostmattermost_server11.2.0, 11.3.0, 11.4.0

Timeline

References

Open in Interactive Console →