CVE-2026-40188CWE-1314

goshs is Missing Write Protection for Parametric Data Values

High · published April 10, 2026

CVSS v3.1
7.7
EPSS
0%
Percentile
24.3
In the wild
Unconfirmed
What it is

goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4.

The record
Technical detail
CVSS v3.1
7.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00318 · 24.3th percentile
Weakness
CWE-1314 · Missing Write Protection for Parametric Data Values
Published
2026-04-10T19:43Z
EPSS history
Timeline
  • 10 APR 19:43Z
    goshs is Missing Write Protection for Parametric Data Values
    cvelistv5