SFTP root escape via prefix-based path validation in goshs
Modified: 6/25/2026
package
pkg:go/github.com/patrickhener/goshs/v2
SFTP root escape via prefix-based path validation in goshs
Modified: 6/25/2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access
Modified: 6/25/2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Modified: 6/25/2026
goshs has ACL Bypass & Path Traversal
Modified: 8/18/2026
goshs has an empty-username SFTP password authentication bypass
Modified: 6/25/2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Modified: 8/18/2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation
Modified: 6/25/2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
Modified: 6/25/2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
Modified: 8/18/2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
Modified: 8/18/2026
goshs has a Path Traversal issue
Modified: 8/18/2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Modified: 6/25/2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Modified: 6/25/2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Modified: 6/25/2026