PT-2026-30022 · Goshs · Goshs

Autobot23920

·

Published

2026-04-03

·

Updated

2026-04-14

·

CVE-2026-35393

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: goshs (affected versions not specified)
Description: A path traversal flaw in goshs allows unauthorized file access and manipulation. The issue resides in the POST multipart upload functionality, specifically within the httpserver/updown.go file (lines 71-174). The vulnerability occurs because the target directory is derived from the unsanitized req.URL.Path variable, enabling attackers to traverse the file system using directory traversal sequences like ../... The filename is sanitized, but the path is not, allowing an attacker to write files to arbitrary locations. The API endpoint ''/upload'' is involved, and the filename parameter in the multipart upload is used to control the final filename on disk. This can lead to unauthenticated arbitrary file writes to any existing directory on the filesystem.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35393
GHSA-JG56-WF8X-QRV5
OPENSUSE-SU-2026:10542-1

Affected Products

Goshs