{"id":"CVE-2026-50891","aliases":["GHSA-rcqf-cpv9-g5jf"],"title":"Filestash allows attackers to escalate privileges via sending a crafted request","summary":"Filestash allows attackers to escalate privileges via sending a crafted request","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","vendor":"mickael-kerjean","product":"github.com/mickael-kerjean/filestash","ecosystem":"go","affected":["github.com/mickael-kerjean/filestash <= 0.2.2-0.20260827111952-cbcd1e96ebc7"],"published":"2026-06-15","updated":"2026-08-27","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rcqf-cpv9-g5jf","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50891"},{"url":"https://gist.github.com/pyuysig/50dc365f54f95396bb67532f02b34bb0"},{"url":"https://github.com/mickael-kerjean/filestash"}],"tags":["osv","go"],"epss":0.0035,"epssPercentile":0.25924,"ingestedAt":"2026-08-27T19:27:47.579Z","slug":"CVE-2026-50891","body":"## Overview\n\nIncorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.\n\n## Affected packages\n\n- `github.com/mickael-kerjean/filestash <= 0.2.2-0.20260827111952-cbcd1e96ebc7`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}