Tag
critical
advisory
goshs Unauthenticated Arbitrary File Deletion via Path Traversal
2 rules 1 TTPThe goshs application is vulnerable to unauthenticated path traversal (CVE-2026-35471) due to a missing return statement in the `deleteFile()` function, allowing attackers to delete arbitrary files and directories using a crafted GET request.
path-traversal
file-deletion
goshs
2r
1t
high
advisory
Goshs Authentication Bypass via Share Token
2 rules 3 TTPs 2 IOCsGoshs is vulnerable to an authentication bypass via share tokens, allowing attackers to bypass authentication checks by using a valid share token in conjunction with other functionalities like WebSocket connections to gain unauthorized access and execute arbitrary commands on the server.
authentication-bypass
code-execution
goshs
2r
3t
2i