Vulnerability Description
goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible for anyone to execute commands on the server. The function `dispatchReadPump` does not checks the option cli `-c`, thus allowing anyone to execute arbitrary command through the use of websockets. Version 1.0.5 fixes the issue.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/patrickhener/goshs/commit/160220974576afe5111485b8d12fd360589
- https://github.com/patrickhener/goshs/security/advisories/GHSA-rwj2-w85g-5cmm
FAQ
What is CVE-2025-46816?
CVE-2025-46816 is a vulnerability with a CVSS score of 9.4 (CRITICAL). goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible for anyone to execute commands on the server. The fun...
How severe is CVE-2025-46816?
CVE-2025-46816 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-46816?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.