Back to overview

CVE-2026-54719

HIGH
7.5
CVSS 3.1
Description
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. This issue is fixed in version 2.1.1. This vulnerability exists due to an incomplete fix for CVE-2026-40189.

Metadata

CVE ID
CVE-2026-54719
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-06-15 23:07 UTC
Published
2026-07-28 21:58 UTC
Last updated
2026-07-28 22:01 UTC
Primary CWE
CWE-862
CWE-862: Missing Authorization
Vendor / Product
goshs-labs / goshs
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
goshs-labs goshs < 2.1.1
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862: Missing Authorization
CWE-863 cna CWE-863: Incorrect Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References (3)
Back to overview