ZeroHour

CVE-2026-34581

PoC
CVSS 3.1
8.1 high
EPSS
<1%p33
Published
()
Modified
Description

goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.

Vendors
goshs
Products
goshs
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.