Vulnerability Description
goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Goshs | Goshs | >= 1.1.0, < 2.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/patrickhener/goshs/commit/6fb224ed15c2ccc0c61a5ebe22f2401eb06Patch
- https://github.com/patrickhener/goshs/releases/tag/v2.0.0-beta.2ProductRelease Notes
- https://github.com/patrickhener/goshs/security/advisories/GHSA-jgfx-74g2-9r6gExploitVendor Advisory
FAQ
What is CVE-2026-34581?
CVE-2026-34581 is a vulnerability with a CVSS score of 8.1 (HIGH). goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh f...
How severe is CVE-2026-34581?
CVE-2026-34581 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34581?
Check the references section above for vendor advisories and patch information. Affected products include: Goshs Goshs.