Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
Go/github.com/patrickhener/goshs/v2 — 5 CVEs · VulnScope
pkg:Go/
github.com/patrickhener/goshs/v2
5 total CVEs
CRITICAL
1
HIGH
3
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2026-40884
goshs has an empty-username SFTP password authentication bypass
from 0, < 2.0.0
HIGH
8.8
CVE-2026-40885
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access
>= 2.0.0-beta.4, < 2.0.0-beta.6
HIGH
8.8
CVE-2026-40876
SFTP root escape via prefix-based path validation in goshs
from 0, < 2.0.0
HIGH
8.1
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation
>= 2.0.0-beta.4, < 2.0.0-beta.6
MEDIUM
6.5
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
from 0, < 2.0.2
CVE-2026-40883
CVE-2026-42091