CVE-2020-14456: Mattermost Desktop

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

Affected products

  • Mattermost Mattermost Desktop: before 4.4.0 (fixed in 4.4.0)

Published 2020-06-19. Last modified 2026-06-17.