PT-2026-32038 · Patrickhener · Goshs

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-40188

CVSS v3.1

7.7

High

AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-40188

Affected Products

Goshs