logo

Critical 9.8 CVSS Flaws in goshs Exposed

ID: cdbc571a-8b8d-523e-b8ff-2e3c8e3c3c77

STIX ID: report--cdbc571a-8b8d-523e-b8ff-2e3c8e3c3c77

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed three critical path-traversal vulnerabilities in goshs that allow unauthenticated attackers to write or delete files anywhere on a host’s filesystem by abusing unsanitized URL-derived paths; two issues are rated CVSS 9.8 and a fixed release v2.0.0-beta.3 is available. Recommended actions include immediate upgrade, using Basic Auth as defense-in-depth, and running the service with non-root privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.