Junglewise Threat Intelligence

CVE-2026-40189: patrickhener goshs authorization bypass in state-changing routes

CVE-2026-40189 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: github.com/patrickhener/goshs (Go), Patrickhener Goshs. Vendors: Go.

Executive brief

goshs, a tool for serving files over HTTP, contains a security flaw in its folder-level protection system. While it correctly asks for a password to view files, it fails to check for that password when an attacker tries to upload, create, or delete files. This allows an unauthenticated person to delete the security configuration file itself, effectively unlocking the folder and gaining full access to private data.

Technical details

A missing authorization vulnerability exists in goshs where state-changing HTTP handlers (upload, put, handleMkdir, and deleteFile) do not invoke the findSpecialFile() or custom auth logic used by read/list handlers. An unauthenticated remote attacker can use PUT or multipart POST requests to write files, or use the ?mkdir and ?delete query parameters to modify the filesystem. By deleting the .goshs ACL configuration file via the unauthenticated ?delete route, an attacker can permanently remove the authorization barrier for a directory, subsequently gaining access to previously protected files. The issue is present in versions up to 1.1.4 and v2.0.0-beta.3; it is addressed in v2.0.0-beta.4.

Affected products

  • patrickhener goshs <= 1.1.4, v2.0.0-beta.3

Timeline

  • 2026-04-09: disclosed
  • 2026-04-10: advisory: GitHub Advisory published
  • 2026-04-10: patched: v2.0.0-beta.4 released

References

Related threats