CVE-2026-62325
critical · 9.1goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.
9.1
CVSS
0.3%
EPSS (exploit prob.)
28th
EPSS percentile
2026-07-28
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-306
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-62325