Browse all 5 CVE security advisories affecting goshs-labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-66064 | goshs has ACL Bypass & Path Traversal — goshs CWE-41 | 5.3 | Medium | 2026-07-28 |
| CVE-2026-66063 | goshs has a Path Traversal issue — goshs CWE-22 | 6.5 | Medium | 2026-07-28 |
| CVE-2026-64863 | goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite — goshs CWE-284 | 9.1 | Critical | 2026-07-28 |
| CVE-2026-54719 | goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of CVE-2026-40189) — goshs CWE-862 | 7.5 | High | 2026-07-28 |
| CVE-2026-62325 | goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) — goshs CWE-306 | 9.1 | Critical | 2026-07-28 |
This page lists every published CVE security advisory associated with goshs-labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.