{"id":"GHSA-964w-f6gj-5236","summary":"goshs has ACL Bypass & Path Traversal","details":"## Summary\n\n`sendFile` derives the served filename from the raw request path while opening the file from the cleaned path, so appending a trailing slash empties the derived name and defeats both the never-serve rule for the ACL file and the block list. \n\n## Finding (Medium): trailing-slash ACL and hidden-file bypass\n\nhttpserver/handler.go, sendFile (lines 789-801) takes the filename from the RAW req.URL.Path while the file itself is opened from the filepath.Clean-ed path. The two disagree, and a trailing slash makes the derived name the empty string. Both protections key on that derived name, so both are defeated: the rule that never serves the .goshs ACL file, and the acl.Block list.\n\nMeasured, with negative controls:\n\n```\nGET /blocked/secret.txt    -\u003e 404          (control, correctly blocked)\nGET /blocked/secret.txt/   -\u003e 200 + contents\nGET /blocked/.goshs/       -\u003e 200, returns the ACL file itself,\n                              including the admin:$2a$... bcrypt hash\n```\n\nUnauthenticated when the ACL is configured block-only (common usage). Stated precisely: AUTHENTICATION IS NOT BYPASSED. An unauthenticated request against a directory protected by authentication still returns 401 under the same trick; I tested that. The claim is specifically that the block list and the ACL-file protection are bypassed. In-tree evidence that sendFile is the defect: the sibling handlers doDir and bulkDownload both derive the name correctly; sendFile is the lone outlier.\n\n## Suggested fixes\n\n1. Derive the served filename from the same cleaned path used to open the file, so the authorization decision and the file access cannot disagree.\n\n## Tooling\n\nAI assistance was used while investigating. The finding was reproduced against a running server on loopback with negative controls, including the 404-versus-200 pair and the authenticated-directory control that shows authentication is not affected.","aliases":["CVE-2026-66064","GO-2026-6134"],"modified":"2026-08-18T15:10:56.498808648Z","published":"2026-07-28T22:26:28Z","database_specific":{"github_reviewed_at":"2026-07-28T22:26:28Z","nvd_published_at":null,"cwe_ids":["CWE-22","CWE-41","CWE-863"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/goshs-labs/goshs/security/advisories/GHSA-964w-f6gj-5236"},{"type":"WEB","url":"https://github.com/goshs-labs/goshs/pull/222"},{"type":"WEB","url":"https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa"},{"type":"PACKAGE","url":"https://github.com/goshs-labs/goshs"}],"affected":[{"package":{"name":"github.com/patrickhener/goshs/v2","ecosystem":"Go","purl":"pkg:golang/github.com/patrickhener/goshs/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.5-0.20260727065949-f3ef599e4091"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.1.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-964w-f6gj-5236/GHSA-964w-f6gj-5236.json"}},{"package":{"name":"goshs.de/goshs/v2","ecosystem":"Go","purl":"pkg:golang/goshs.de/goshs/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.5-0.20260727065949-f3ef599e4091"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.1.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-964w-f6gj-5236/GHSA-964w-f6gj-5236.json"}},{"package":{"name":"github.com/patrickhener/goshs","ecosystem":"Go","purl":"pkg:golang/github.com/patrickhener/goshs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-964w-f6gj-5236/GHSA-964w-f6gj-5236.json"}},{"package":{"name":"goshs.de/goshs","ecosystem":"Go","purl":"pkg:golang/goshs.de/goshs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-964w-f6gj-5236/GHSA-964w-f6gj-5236.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}