goshs是Patrick Hener个人开发者的一个用Go编写的简单HTTP Server。 goshs 2.0.0-beta.6之前版本存在路径遍历漏洞,该漏洞源于SFTP子系统sanitizePath函数使用基于前缀的路径验证,可能导致经过身份验证的SFTP用户读写配置根目录之外的文件系统路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| patrickhener | goshs | < 2.0.0-beta.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40884 | 9.8 CRITICAL | goshs: Empty-username SFTP password authentication bypass in goshs |
| CVE-2026-40903 | 9.1 CRITICAL | Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence |
| CVE-2026-40883 | goshs: CSRF in state-changing GET routes enables authenticated file deletion and directory | |
| CVE-2026-40885 | goshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized acce |
No comments yet