Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.
References
Configurations
No configuration.
History
13 Mar 2026, 19:54
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-13 19:54
Updated : 2026-03-13 19:54
NVD link : CVE-2026-30943
Mitre link : CVE-2026-30943
CVE.ORG link : CVE-2026-30943
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
