Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

patrickhener — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting patrickhener. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Patrickhener focuses on identifying vulnerabilities in web applications and enterprise software, with a core use case in security research and penetration testing. Historically, their contributions span multiple vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation, often targeting authentication mechanisms and API endpoints. While no major public incidents are directly attributed to this researcher, their 13 CVEs demonstrate consistent findings in complex systems, particularly in open-source platforms and cloud services. Their work emphasizes uncovering flaws in access controls and input validation, contributing to improved security postures across affected vendors.

Top products by patrickhener: goshs
CVE ID Title CVSS Severity Published
CVE-2026-50139 goshs: Share-link ?token=… redemption races past download limit — goshs CWE-362 5.9 Medium 2026-08-18
CVE-2026-50138 goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags — goshs CWE-284 8.1 High 2026-08-18
CVE-2026-42091 goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS — goshs CWE-352 6.5 Medium 2026-05-04
CVE-2026-40903 Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence — goshs CWE-829 9.1 Critical 2026-04-21
CVE-2026-40885 goshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized access — goshs CWE-200 9.1AI Critical AI 2026-04-21
CVE-2026-40884 goshs: Empty-username SFTP password authentication bypass in goshs — goshs CWE-306 9.8 Critical 2026-04-21
CVE-2026-40883 goshs: CSRF in state-changing GET routes enables authenticated file deletion and directory creation — goshs CWE-352 8.1AI High AI 2026-04-21
CVE-2026-40876 SFTP root escape via prefix-based path validation in goshs — goshs CWE-22 8.8AI High AI 2026-04-21
CVE-2026-40189 goshs has a file-based ACL authorization bypass in goshs state-changing routes — goshs CWE-862 9.8AI Critical AI 2026-04-10
CVE-2026-40188 goshs is Missing Write Protection for Parametric Data Values — goshs CWE-1314 7.7 High 2026-04-10
CVE-2026-35471 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs — goshs CWE-22 9.1AI Critical AI 2026-04-06
CVE-2026-35393 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload — goshs CWE-22 9.8AI Critical AI 2026-04-06
CVE-2026-35392 goshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload — goshs CWE-22 9.1AI Critical AI 2026-04-06
CVE-2026-34581 goshs has Auth Bypass via Share Token — goshs CWE-288 8.1 High 2026-04-02
CVE-2025-46816 goshs route not protected, allows command execution — goshs CWE-284 9.8AI Critical AI 2025-05-06

This page lists every published CVE security advisory associated with patrickhener. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.