github.com/patrickhener/goshs

govv1.1.4

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · SFTP · SMB · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful python3 -m http.server replacement.

License MITpermissive47 versions11 maintainers0 deps615 weekly dl
patrickhener/goshs
40
/ 100
Health
do not use

github.com/patrickhener/goshs has critical vulnerabilities — do not use

Update to >= 2.0.2 to fix known vulnerabilities

  • 3 high severity vulnerabilities
  • 5 critical vulnerabilities
Health breakdown0 – 100
20/25
maintenance
3/20
popularity
0/25
security
12/15
maturity
5/15
community
Vulnerabilities
10
5 critical3 high1 medium1 low
Advisories (10)
SeverityIDSummaryFixed in
highCVE-2026-40188goshs is Missing Write Protection for Parametric Data Values
highCVE-2026-40876SFTP root escape via prefix-based path validation in goshs2.0.0
criticalCVE-2026-35471goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)1.1.5-0.20260401172448-237f3af891a9
lowGHSA-7qx6-f23w-3w7fUnauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
criticalCVE-2026-40884goshs has an empty-username SFTP password authentication bypass2.0.0
criticalCVE-2026-35392goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload1.1.5-0.20260401172448-237f3af891a9
criticalCVE-2026-35393goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload1.1.5-0.20260401172448-237f3af891a9
highCVE-2026-34581goshs has Auth Bypass via Share Token
mediumGHSA-rhf7-wvw3-vjvmgoshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS2.0.2
criticalCVE-2026-40189goshs has a file-based ACL authorization bypass in goshs state-changing routes

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/patrickhener/goshs

Last updated · 2026-03-13T14:11:55Z