CVE-2026-28682: Forceu Gokapi

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any authenticated listener and includes file_id values that are not scoped to the requesting user. This issue has been patched in version 2.2.3.

Affected products

  • Forceu Gokapi: before 2.2.3 (fixed in 2.2.3)

Published 2026-03-06. Last modified 2026-06-17.