goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goshs
Goshs goshs |
|
| CPEs | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta2:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta3:*:*:*:go:*:* |
|
| Vendors & Products |
Goshs
Goshs goshs |
Mon, 13 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Patrickhener
Patrickhener goshs |
|
| Vendors & Products |
Patrickhener
Patrickhener goshs |
Fri, 10 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4. | |
| Title | goshs is Missing Write Protection for Parametric Data Values | |
| Weaknesses | CWE-1314 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-10T19:43:45.197Z
Updated: 2026-04-13T15:35:32.574Z
Reserved: 2026-04-09T20:59:17.620Z
Link: CVE-2026-40188
Updated: 2026-04-13T15:23:28.408Z
Status : Analyzed
Published: 2026-04-10T20:16:23.733
Modified: 2026-04-14T20:15:28.567
Link: CVE-2026-40188
No data.
ReportizFlow