CVE-2026-40189: Goshs State Changing Handler Missing Acl Check
State-changing FileServer handler performs a filesystem-mutating operation (file create/open-for-write, remove, remove-all, mkdir, or multipart body read) without first calling fs.applyCustomAuth(...) to enforce the per-folder .goshs ACL/basic-auth policy. The read paths (doDir/doFile) gate access through findSpecialFile/findEffectiveACL + applyCustomAuth, b
greprules fetch cve-2026-40189-goshs-state-changing-handler-missing-acl-check --engine opengrepDescription
State-changing FileServer handler performs a filesystem-mutating operation (file create/open-for-write, remove, remove-all, mkdir, or multipart body read) without first calling fs.applyCustomAuth(...) to enforce the per-folder .goshs ACL/basic-auth policy. The read paths (doDir/doFile) gate access through findSpecialFile/findEffectiveACL + applyCustomAuth, b
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.