Robuta

https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/v2/CVE-2026-40883/ goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory... CVE-2026-40883 goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation: goshs contains a cross-site request... https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/v2/GHSA-rhf7-wvw3-vjvm/ goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS | GitLab... GHSA-rhf7-wvw3-vjvm goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS: The PUT upload handler (httpserver/updown.go) lacks... https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/GHSA-c29w-qq4m-2gcv/ Empty-username SFTP password authentication bypass in goshs | GitLab Advisory Database (GLAD) GHSA-c29w-qq4m-2gcv Empty-username SFTP password authentication bypass in goshs: goshs contains an SFTP authentication bypass when the documented... password authentication https://demo.goshs.de/ goshs Demo demo https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/v2/CVE-2026-40876/ SFTP root escape via prefix-based path validation in goshs | GitLab Advisory Database (GLAD) CVE-2026-40876 SFTP root escape via prefix-based path validation in goshs: goshs contains an SFTP root escape caused by prefix-based path validation. An... https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/CVE-2026-42091/ goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS | GitLab... CVE-2026-42091 goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS: The PUT upload handler (httpserver/updown.go) lacks the... https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/CVE-2025-46816/ goshs route not protected, allows command execution | GitLab Advisory Database (GLAD) CVE-2025-46816 goshs route not protected, allows command execution: It seems that when running goshs without arguments it is possible for anyone to execute... command executionrouteprotectedallows https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/CVE-2026-40188/ goshs is Missing Write Protection for Parametric Data Values | GitLab Advisory Database (GLAD) CVE-2026-40188 goshs is Missing Write Protection for Parametric Data Values: The SFTP command rename sanitizes only the source path and not the destination, so...