Skip to content
cyberMEDIUM2026-04-21 19:34 UTC

CVE-2026-40876 - SFTP root escape via prefix-based path validation in goshs

CVE ID :CVE-2026-40876 Published : April 21, 2026, 7:34 p.m. | 32 minutes ago Description :goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesyst

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber