9.1
CVE-2026-40903
- EPSS 0.25%
- Veröffentlicht 21.04.2026 19:43:36
- Zuletzt bearbeitet 01.05.2026 16:15:06
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.154 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
https://github.com/patrickhener/goshs/security/advisories/GHSA-hpxj-9fgp-fhhf