CVE-2026-40188 is a path traversal vulnerability affecting goshs, a SimpleHTTPServer implementation written in Go, in versions 1.0.7 through before 2.0.0-beta.4. The flaw exists in the SFTP rename command, which sanitizes only the source path but fails to validate the destination path, allowing an attacker to write files outside the designated root directory. The vulnerability has been remediated in version 2.0.0-beta.4. The vulnerability carries a HIGH severity rating with a CVSS score of 7.7, as it requires only low attack complexity and can be exploited remotely by authenticated users without user interaction. The attack has a wide scope with high integrity impact, enabling attackers to modify or create arbitrary files on the system, though confidentiality and availability are not directly affected. There is currently no evidence of active exploitation in the wild, as the CVE is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on security hot lists. The EPSS score of 0.00029 indicates a very low probability of exploitation relative to other published CVEs, suggesting minimal community attention and likely no publicly available exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.7, < 2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta2:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta3:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.