Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-66063

Опубликовано: 28 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. to create a file outside the served tree. This issue is fixed in version 2.1.5.

EPSS

Процентиль: 14%
0.00233
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
10 дней назад

goshs has a Path Traversal issue

EPSS

Процентиль: 14%
0.00233
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22