---
id: CVE-2026-50891
aliases:
  - GHSA-rcqf-cpv9-g5jf
title: >-
  Filestash allows attackers to escalate privileges via sending a crafted
  request
summary: >-
  Filestash allows attackers to escalate privileges via sending a crafted
  request
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
vendor: mickael-kerjean
product: github.com/mickael-kerjean/filestash
ecosystem: go
affected:
  - github.com/mickael-kerjean/filestash <= 0.2.2-0.20260827111952-cbcd1e96ebc7
published: '2026-06-15'
updated: '2026-08-27'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-rcqf-cpv9-g5jf'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50891'
  - url: 'https://gist.github.com/pyuysig/50dc365f54f95396bb67532f02b34bb0'
  - url: 'https://github.com/mickael-kerjean/filestash'
tags:
  - osv
  - go
epss: 0.0035
epssPercentile: 0.25924
ingestedAt: '2026-08-27T19:27:47.579Z'
---

## Overview

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

## Affected packages

- `github.com/mickael-kerjean/filestash <= 0.2.2-0.20260827111952-cbcd1e96ebc7`

## Remediation

Refer to the advisory for the patched release.
