Executive brief
goshs is a file server tool used by developers and security professionals to quickly share files over a network. A security flaw in the SFTP component allows unauthorized users to access, download, or delete files without providing a password if the server is configured with a username but no password. This could lead to the complete exposure or loss of sensitive data hosted on the server.
Technical details
A vulnerability in `sftpserver/sftpserver.go` exists because the SFTP password handler is only initialized if both a username and password are non-empty (`Username != "" && Password != ""`). When a user starts goshs with a username but an empty password (e.g., `-b 'admin:' -sftp`) and no public key file (`-fkf`), the `PasswordHandler` remains nil. The underlying `gliderlabs/ssh` library defaults to `NoClientAuth = true` when all authentication handlers are nil, allowing remote attackers to connect via SFTP without any credentials. This is an incomplete fix for a previous vulnerability (CVE-2026-40884) which only addressed empty usernames. The issue is resolved in version 2.1.4 by changing the logic to use an OR (`||`) operator, ensuring the handler is installed if either credential is provided.
Affected products
- goshs-labs goshs >= 2.1.3, < 2.1.4
Timeline
- 2026-06-26: disclosed: GHSA-rjrw-mjq6-hpmm published
- 2026-07-03: patched: Version 2.1.4 released
- 2026-07-28: advisory: NVD published CVE-2026-62325