Vulnerability Description
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forceu | Gokapi | < 2.2.4 |
Related Weaknesses (CWE)
References
- https://github.com/Forceu/Gokapi/releases/tag/v2.2.4ProductRelease Notes
- https://github.com/Forceu/Gokapi/security/advisories/GHSA-j6jp-78w8-34x6Vendor Advisory
FAQ
What is CVE-2026-30943?
CVE-2026-30943 is a vulnerability with a CVSS score of 4.1 (MEDIUM). Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list v...
How severe is CVE-2026-30943?
CVE-2026-30943 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30943?
Check the references section above for vendor advisories and patch information. Affected products include: Forceu Gokapi.