CVE-2026-62325: CWE-306: Missing Authentication for Critical Function in goshs-labs goshs
CVE-2026-62325 is a critical vulnerability in goshs, a single-binary file server, affecting versions from 2.1.3 up to but not including 2.1.4. The issue arises from improper authentication checks in the SFTP password handler, allowing unauthenticated file access when certain flags are used. This vulnerability is fixed in version 2.1.4.
AI Analysis
Technical Summary
The vulnerability in goshs versions >=2.1.3 <2.1.4 is due to missing authentication for a critical function in the SFTP server password handler. Specifically, the handler only checked that Username and Password were non-empty strings, but when goshs was run with the -b 'admin:' and -sftp flags without the -fkf flag, the SFTP authentication handlers were left unset. This allowed unauthenticated users to access files via SFTP. The issue is resolved in version 2.1.4.
Potential Impact
An attacker can gain unauthenticated access to files via the SFTP server in affected versions, leading to full confidentiality and integrity compromise of the file server contents. There is no impact on availability. The CVSS v3.1 score is 9.1 (critical), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality and integrity impact.
Mitigation Recommendations
This vulnerability is fixed in goshs version 2.1.4. Users should upgrade to version 2.1.4 or later to remediate the issue. No other mitigations are indicated in the vendor advisory or CVE description.
CVE-2026-62325: CWE-306: Missing Authentication for Critical Function in goshs-labs goshs
Description
CVE-2026-62325 is a critical vulnerability in goshs, a single-binary file server, affecting versions from 2.1.3 up to but not including 2.1.4. The issue arises from improper authentication checks in the SFTP password handler, allowing unauthenticated file access when certain flags are used. This vulnerability is fixed in version 2.1.4.
CVSS v3.1
Score 9.1critical
Affected software
goshs-labs
goshs
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in goshs versions >=2.1.3 <2.1.4 is due to missing authentication for a critical function in the SFTP server password handler. Specifically, the handler only checked that Username and Password were non-empty strings, but when goshs was run with the -b 'admin:' and -sftp flags without the -fkf flag, the SFTP authentication handlers were left unset. This allowed unauthenticated users to access files via SFTP. The issue is resolved in version 2.1.4.
Potential Impact
An attacker can gain unauthenticated access to files via the SFTP server in affected versions, leading to full confidentiality and integrity compromise of the file server contents. There is no impact on availability. The CVSS v3.1 score is 9.1 (critical), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality and integrity impact.
Mitigation Recommendations
This vulnerability is fixed in goshs version 2.1.4. Users should upgrade to version 2.1.4 or later to remediate the issue. No other mitigations are indicated in the vendor advisory or CVE description.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-13T19:27:58.315Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a692bbe9c2644c7f84c1486
Added to database: 07/28/2026, 22:22:54 UTC
Last enriched: 08/05/2026, 15:13:21 UTC
Last updated: 09/11/2026, 22:06:34 UTC
Views: 79
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.