Junglewise Threat Intelligence

CVE-2026-34581: Patrickhener goshs authentication bypass via Share Token

CVE-2026-34581 · Severity: high · CVSS 8.1 · Published 2026-04-02

Technologies: github.com/patrickhener/goshs (Go), Patrickhener Goshs. Vendors: Go.

Executive brief

goshs is a simple web server used to share files and provide remote command-line access. A security flaw allows anyone with a valid "share token"—normally used only to download a specific file—to bypass all security checks and gain full control over the server. This could allow an attacker to steal sensitive data, delete files, or execute malicious commands on the host system.

Technical details

An authentication bypass exists in the BasicAuthMiddleware of goshs due to improper validation logic. The middleware prioritizes checking for a '?token=' parameter; if a valid share token (intended for single-file access) is present, the middleware grants full access and skips subsequent authentication checks. An attacker with a valid share token can append additional query parameters, such as '?ws', to upgrade the connection to a WebSocket. This grants access to restricted features including directory listings, file deletion, and CLI command execution if the module is enabled. The issue is fixed in version 2.0.0-beta.2.

Affected products

  • patrickhener goshs >= 1.1.0, < 2.0.0-beta.2

Timeline

  • 2026-03-30: advisory: Vendor advisory published on GitHub
  • 2026-03-30: patched: Version 2.0.0-beta.2 released
  • 2026-04-02: disclosed: CVE-2026-34581 published

References

Related threats