PT-2026-33234 · Goshs · Goshs
R1Zzg0D
·
Published
2026-04-14
·
Updated
2026-04-27
·
CVE-2026-40885
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
goshs versions 2.0.0-beta.4 through 2.0.0-beta.5
Description
When deployed without global basic authentication, the server leaks file-based Access Control List (ACL) credentials through its public collaborator feed. Requests to folders protected by
.goshs are logged before authorization is enforced. Consequently, the collaborator websocket broadcasts raw request headers, including the Authorization variable, to all connected clients. An unauthenticated observer can capture a victim's folder-specific basic-auth header and replay it to read, upload, overwrite, and delete files within the protected subtree.Recommendations
Update to version 2.0.0-beta.6.
As a temporary workaround, restrict access to the collaborator websocket and panel using authentication boundaries.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Goshs