Executive brief
goshs is a simple web server tool used for sharing files over a network. A security flaw allows an unauthenticated attacker to upload or overwrite any file on the host system by bypassing directory restrictions. This could lead to a complete system takeover, data loss, or the installation of malicious software.
Technical details
A path traversal vulnerability exists in the PUT upload handler of goshs within `httpserver/updown.go`. The application fails to sanitize the `req.URL.Path` input, using raw string concatenation to determine the file save location without performing `filepath.Clean` or validating that the path remains within the intended webroot. An unauthenticated remote attacker can use URL-encoded traversal sequences (e.g., `%2e%2e/`) to write or overwrite arbitrary files anywhere on the host filesystem. This can be leveraged for remote code execution by overwriting sensitive system files or configuration. The issue is resolved in version 2.0.0-beta.3.
Affected products
- patrickhener goshs < 2.0.0-beta.3
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-06: disclosed: CVE published to NVD