goshs is Missing Write Protection for Parametric Data Values
Modified: 6/8/2026
package
pkg:go/github.com/patrickhener/goshs
goshs is Missing Write Protection for Parametric Data Values
Modified: 6/8/2026
SFTP root escape via prefix-based path validation in goshs
Modified: 6/25/2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Modified: 6/25/2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Modified: 6/25/2026
goshs has ACL Bypass & Path Traversal
Modified: 8/18/2026
goshs has an empty-username SFTP password authentication bypass
Modified: 6/25/2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload
Modified: 6/25/2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Modified: 8/18/2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload
Modified: 6/25/2026
goshs has Auth Bypass via Share Token
Modified: 6/25/2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
Modified: 6/25/2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
Modified: 8/18/2026
goshs route not protected, allows command execution
Modified: 5/15/2025
goshs has a Path Traversal issue
Modified: 8/18/2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes
Modified: 6/25/2026
goshs route not protected, allows command execution in github.com/patrickhener/goshs
Modified: 3/3/2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Modified: 5/20/2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Modified: 6/25/2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Modified: 8/18/2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Modified: 8/18/2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Modified: 8/18/2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs
Modified: 8/18/2026