CVE-2026-6850 | Mattermost up to 10.11.19/11.6.4/11.7.2 Client-Side Markdown Parser attachment cross site scripting
A vulnerability marked as problematic has been reported in Mattermost up to 10.11.19/11.6.4/11.7.2. Affected by this vulnerability is an unknown functionality of the component Client-Side Markdown Parser. The manipulation of the argument attachment leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-6850. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More