8.1
CVE-2026-34581
- EPSS 0.39%
- Veröffentlicht 02.04.2026 18:04:35
- Zuletzt bearbeitet 15.04.2026 17:38:30
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
goshs has Auth Bypass via Share Token
goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.308 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
|
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
https://github.com/patrickhener/goshs/security/advisories/GHSA-jgfx-74g2-9r6g
https://github.com/patrickhener/goshs/commit/6fb224ed15c2ccc0c61a5ebe22f2401eb06e9216
https://github.com/patrickhener/goshs/releases/tag/v2.0.0-beta.2