CVE-2026-54719
HIGHgoshs < 2.1.1 - Unauthenticated Bulk Download ACL Bypass
Title source: manualDescription
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. This issue is fixed in version 2.1.1. This vulnerability exists due to an incomplete fix for CVE-2026-40189.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/goshs-labs/goshs/security/advisories/GHSA-rmxw-pq4x-3fvh
X_Refsource_Misc x_refsource_misc
https://github.com/goshs-labs/goshs/commit/7cf911a26ace737e1a55b7dc073e307a25f7fd1d
X_Refsource_Misc x_refsource_misc
https://github.com/goshs-labs/goshs/releases/tag/v2.1.1
Scores
CVSS v3
7.5
EPSS
0.0028
EPSS Percentile
20.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
CWE-863
Status
published
Products (5)
goshs/v2
0 - 2.1.1Go
goshs-labs/goshs
< 2.1.1
goshs.de/goshs
0 - 1.1.4Go
patrickhener/goshs
0 - 1.1.4Go
patrickhener/goshs
0 - 2.1.1Go
Published
Jul 28, 2026
Tracked Since
Jul 29, 2026