Junglewise Threat Intelligence
CVE-2026-3112: GO-2026-5092 - Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermos
CVE-2026-3112 · Severity: low · CVSS 3.1 · Published 2026-06-25
Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go.
Executive brief
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server
Affected products
- Go github.com/mattermost/mattermost-server/v5
- Go github.com/mattermost/mattermost-server/v6
- Go github.com/mattermost/mattermost/server/v8
- Go github.com/mattermost/mattermost-server