Executive brief
goshs is a tool used to serve files over HTTP. A vulnerability in its redirect endpoint allows attackers to redirect users to malicious websites and inject custom web headers. This can be used to trick users into visiting phishing sites or to bypass security settings like HTTPS requirements, potentially compromising user sessions or data integrity.
Technical details
The `GET /?redirect` endpoint in `goshs` (v1 and v2 beta) fails to validate the `url` parameter, leading to an open redirect. Additionally, it accepts a `header` parameter that allows attackers to inject arbitrary 'Name: Value' pairs into the HTTP response headers without an allow-list. The endpoint lacks authentication in default deployments, does not implement CSRF protection, and ignores the 'Invisible' stealth mode flag. This combination allows attackers to perform cross-subdomain session fixation via `Set-Cookie` or force TLS downgrades by overwriting `Strict-Transport-Security` headers. Exploitation is possible via a simple network request to the affected endpoint.
Affected products
- patrickhener goshs <= 1.1.4
- patrickhener goshs/v2 <= 2.0.0-beta.6
Timeline
- 2026-04-13: disclosed
- 2026-04-14: advisory: Published to GitHub Advisory Database
References
- https://api.github.com/users/wooseokdotkim
- https://github.com/wooseokdotkim
- https://api.github.com/users/wooseokdotkim/gists%7B/gist_id%7D
- https://api.github.com/users/wooseokdotkim/repos
- https://avatars.githubusercontent.com/u/121649701?v=4
- https://api.github.com/users/wooseokdotkim/events%7B/privacy%7D