Back to CVE List

CVE-2026-62325

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.1 / 10

Vulnerability Description

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.

Vulnerability Details

Published Date
Last Modified
Source
GitHub
Vendor
go
Product
github.com/patrickhener/goshs/v2

External References

Discussion (0)

Add Comment

No comments yet. Be the first!