Loading market data...
← Back to CVE feed

CVE-2026-34581

HIGH CVSS 8.1 View on NVD ↗

Description

goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Published: Apr 02, 2026 19:21 UTC Modified: Apr 03, 2026 16:10 UTC