PT-2026-33233 · Goshs · Goshs
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
goshs versions prior to 2.0.0-beta.6
Description
goshs contains an SFTP authentication bypass that occurs when the server is started with the
-sftp flag and the basic-auth syntax -b ':pass' (where the username is left empty). In this configuration, the software fails to install an SFTP password handler, allowing an unauthenticated network attacker to connect to the SFTP service and access files without providing a password. This allows unauthorized reading, uploading, renaming, and deleting of files within the configured SFTP root, depending on the server mode and filesystem permissions.Recommendations
Update goshs to version 2.0.0-beta.6.
As a temporary workaround, avoid using the
-b ':pass' syntax when starting the server with the -sftp flag.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Goshs