Executive brief
goshs is a simple web server tool used to share files over a network. A security flaw allows an attacker to upload files to any location on the server's hard drive without needing a password. This could allow an attacker to overwrite critical system files, potentially leading to a full takeover of the server or a complete loss of data.
Technical details
A path traversal vulnerability (CWE-22) exists in the 'goshs' web server within the POST multipart upload handler located in 'httpserver/updown.go'. While the filename itself is sanitized, the target directory is derived directly from the unsanitized 'req.URL.Path'. By using URL-encoded traversal sequences (e.g., %2e%2e/) in the upload path, an unauthenticated remote attacker can escape the intended webroot. This allows for arbitrary file writes to any directory on the host filesystem that the server process has permissions to access. The issue is fixed in version 2.0.0-beta.3.
Affected products
- patrickhener goshs < 2.0.0-beta.3
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-06: disclosed: CVE published to NVD
- 2026-04-06: patched: Fix released in version 2.0.0-beta.3