Affected by GO-2026-4953
and 15 other vulnerabilities
GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
GO-2026-5469: goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs
GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs