CVE-2025-46816: Patrickhener Goshs
Critical severity, CVSS 9.4. EPSS: 0.7% chance of exploitation in the next 30 days.
goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible for anyone to execute commands on the server. The function `dispatchReadPump` does not checks the option cli `-c`, thus allowing anyone to execute arbitrary command through the use of websockets. Version 1.0.5 fixes the issue.
Affected products
- Patrickhener Goshs: from 0.3.4, before 1.0.5 (fixed in 1.0.5)
Published 2025-05-06. Last modified 2026-06-17.