What is CVE-2026-66063?
CVE-2026-66063 is a path traversal vulnerability in the 'goshs' file server. Before version 2.1.5, the multipart upload handler fails to sanitize `..` sequences in filenames, allowing an unauthenticated attacker to upload and create files outside the intended directory. Users should immediately upgrade to version 2.1.5 or later.
Azərbaycanca: CVE-2026-66063, 'goshs' fayl serverində yol keçmə (path traversal) zəifliyidir. Versiya 2.1.5-dən əvvəl, autentifikasiya olmadan yükləmə zamanı fayl adındakı `..` simvolları zərərsizləşdirilmir, bu da uzaqdan hücumçuya serverdə ixtiyari fayl yaratmağa imkan verir. İstifadəçilər təcili olaraq 2.1.5 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
How does CVE-2026-66063 affect the 'goshs' file server?
CVE-2026-66063 is a path traversal vulnerability in the 'goshs' file server. Before version 2.1.5, the multipart upload handler fails to sanitize `..` sequences in filenames, allowing an unauthenticated attacker to upload and create files outside the intended directory.
What should I do to protect against CVE-2026-66063?
Users should immediately upgrade to version 2.1.5 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.