CVE-2026-40903 is an ArtiPACKED vulnerability affecting goshs (a Go-based SimpleHTTPServer) versions prior to 2.0.0-beta.6, which allows unauthorized leakage of GITHUB_TOKEN credentials through workflow artifacts despite the token not being present in the repository source code. The vulnerability presents a critical security risk with a CVSS score of 9.1, characterized by a network-based attack vector requiring no authentication or user interaction, making it easily exploitable by remote threat actors. The attack can result in complete compromise of confidentiality and integrity of systems, as demonstrated by the ability to extract sensitive authentication tokens that could facilitate further unauthorized access or actions. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, and community attention remains minimal as reflected in the moderate FAUCET Risk Score of 52.0. Organizations running goshs versions prior to 2.0.0-beta.6 should prioritize immediate patching to mitigate the risk of credential exposure and potential lateral movement by attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta2:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta3:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta4:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.