goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.
References
| Link | Resource |
|---|---|
| https://github.com/patrickhener/goshs/commit/6fb224ed15c2ccc0c61a5ebe22f2401eb06e9216 | Patch |
| https://github.com/patrickhener/goshs/releases/tag/v2.0.0-beta.2 | Product Release Notes |
| https://github.com/patrickhener/goshs/security/advisories/GHSA-jgfx-74g2-9r6g | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Apr 2026, 17:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/patrickhener/goshs/commit/6fb224ed15c2ccc0c61a5ebe22f2401eb06e9216 - Patch | |
| References | () https://github.com/patrickhener/goshs/releases/tag/v2.0.0-beta.2 - Product, Release Notes | |
| References | () https://github.com/patrickhener/goshs/security/advisories/GHSA-jgfx-74g2-9r6g - Exploit, Vendor Advisory | |
| First Time |
Goshs goshs
Goshs |
|
| CPE | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* |
02 Apr 2026, 19:21
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 19:21
Updated : 2026-04-15 17:38
NVD link : CVE-2026-34581
Mitre link : CVE-2026-34581
CVE.ORG link : CVE-2026-34581
JSON object : View
Products Affected
goshs
- goshs
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
