CVE-2026-66063Medium· 6.5▾ Sunlitgoshs has a Path Traversal issue
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
The multipart upload filename fix splits on the path separator but never rejects dot-dot, allowing a write outside the served tree.
The multipart filename fix (updown.go lines 135-136) splits on the path separator but never rejects "..". Uploading with filename=".." results in os.Create against the parent of the upload folder with a trailing marker character, outside the served tree, and the subsequent failed rename leaves that file behind. Verified: a file containing ESCAPED_WRITE_PROOF was written outside the webroot, unauthenticated, with the default configuration. Not claimed: a Windows-specific variant (Go's Part.FileName() already applies filepath.Base).
AI assistance was used while investigating. The finding was reproduced against a running server on loopback.
goshs.de/goshs/v2 <= 2.1.4github.com/patrickhener/goshs/v2 <= 2.1.4goshs.de/goshs <= 1.1.4github.com/patrickhener/goshs <= 1.1.4Upgrade to a patched release:
goshs.de/goshs/v2 2.1.5-0.20260727065949-f3ef599e4091github.com/patrickhener/goshs/v2 2.1.5-0.20260727065949-f3ef599e4091Connected by shared product, vendor, weakness, or advisory.
CVE-2026-64863Critical· 9.1goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE-2026-50138High· 8.1goshs is a SimpleHTTPServer written in Go
CVE-2026-50139Medium· 5.9goshs is a SimpleHTTPServer written in Go
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4
CVE-2023-7249Critical· 9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.
CVE-2020-3365Medium· 4.3A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories