CVE-2026-62325
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
9.1 / 10
Vulnerability Description
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
go
Product
github.com/patrickhener/goshs/v2
Discussion (0)
Add Comment
No comments yet. Be the first!