Junglewise Threat Intelligence

CVE-2026-40188: patrickhener goshs path traversal in SFTP rename command

CVE-2026-40188 · Severity: high · CVSS 7.7 · Published 2026-04-10

Technologies: github.com/patrickhener/goshs (Go), Patrickhener Goshs. Vendors: Go.

Executive brief

goshs is a tool used to serve files over HTTP and SFTP. A security flaw in its SFTP implementation allows an authenticated user to move or rename files to locations outside of the intended shared folder. This could allow an attacker to overwrite critical system files, such as configuration files or security keys, potentially leading to full system takeover.

Technical details

A path traversal vulnerability exists in the SFTP 'rename' implementation of goshs. While the source path is correctly sanitized against the root directory, the destination path (r.Target) is passed directly to the os.Rename function without validation. An authenticated attacker can exploit this by uploading a file and then using the SFTP rename command to move that file to an arbitrary location on the host filesystem. This can result in arbitrary file overwrite, which may lead to remote code execution if sensitive files like authorized_keys or system configurations are targeted. The issue is addressed in version 2.0.0-beta.4.

Affected products

  • patrickhener goshs >= 1.0.7, <= 1.1.4

Timeline

  • 2026-04-09: disclosed
  • 2026-04-10: advisory

References

Related threats