Description

goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4.

INFO

Published Date :

2026-04-10T19:43:45.197Z

Last Modified :

2026-04-10T19:43:45.197Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-40188 vulnerability.

No data.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact