Executive brief
goshs is a tool used to serve files over the web. A security flaw allows users to bypass security restrictions like "read-only" or "no-delete" when using the WebDAV feature. This means an authorized user could delete or modify files even if the administrator explicitly configured the server to prevent such actions.
Technical details
The vulnerability is an improper access control issue (CWE-284) within the WebDAV implementation of goshs. While the primary HTTP handler correctly enforces mode-restriction flags, the WebDAV mux (located in httpserver/server.go) fails to apply the ReadOnly, UploadOnly, or NoDelete checks before passing requests to the underlying WebDAV handler. An attacker with valid credentials can use WebDAV methods like PUT, DELETE, MKCOL, MOVE, and COPY to bypass intended file system restrictions. This issue is resolved in version 2.1.0.
Affected products
- patrickhener goshs <= 2.0.9
Timeline
- 2026-05-27: other: Vulnerability reproduced by researcher
- 2026-05-28: disclosed: Advisory published by maintainer
- 2026-07-01: advisory: Published to GitHub Advisory Database
References
- https://api.github.com/users/black-shadow-007
- https://github.com/black-shadow-007
- https://api.github.com/users/black-shadow-007/gists%7B/gist_id%7D
- https://api.github.com/users/black-shadow-007/repos
- https://avatars.githubusercontent.com/u/205796698?v=4
- https://api.github.com/users/black-shadow-007/events%7B/privacy%7D