Uncontrolled File Upload Vulnerability in goshs File Server by Goshs Labs
CVE-2026-66063

6.5MEDIUM

Key Information:

Vendor

Goshs-labs

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-66063?

The goshs file server, designed for red teamers and developers, is susceptible to a vulnerability that allows unauthenticated file uploads. Specifically, the multipart upload handler does not adequately enforce restrictions on the 'FileName' parameter, permitting attackers to craft an upload with a filename containing '..' which can result in files being created outside the intended directory structure. This flaw has been addressed in version 2.1.5, thereby reinforcing security and preventing potential exploitation.

Affected Version(s)

goshs < 2.1.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.