github.com/forceu/gokapi
Go10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/forceu/gokapipage 1 of 1
- CVE-2025-48494MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.0.0-20250530191232-343cc566cfd72025-06-02
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encryption, a stored cross-site scripting vulnerability can be exploited by uploading a file with JavaScript code embedded …
- CVE-2025-48495MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.0.0-20250530185940-65ddbc68fbfd2025-06-02
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly name of an API key, an authenticated user could inject JS into the API key overview, which would also be executed when a…
- CVE-2026-28682MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2.2.32026-03-06
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any authenticated listener and inc…
- CVE-2026-28683HIGHCVSS 8.7EG 8.7✓ Fixed in 2.2.32026-03-06
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads SVG and creates a hotlink for it, they can achieve stored XSS. This issue has b…
- CVE-2026-29060MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2.2.32026-03-06
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create or modify file requests is able to create a short-lived API key that has t…
- CVE-2026-29061MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.2.32026-03-06
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerability in the user rank demotion logic allows a demoted user's existing API keys to retain …
- CVE-2026-29084MEDIUMCVSS 4.6EG 4.6✓ Fixed in 2.2.32026-03-06
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the login flow accepts credential-bearing requests without CSRF protection mechanisms tied to the browser session context…
- CVE-2026-30943MEDIUMCVSS 4.1EG 4.1✓ Fixed in 2.2.42026-03-13
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOther…
- CVE-2026-30955MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.2.42026-03-13
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete…
- CVE-2026-30961MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.2.42026-03-13
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunked upload completion path for file requests does not validate the total file size against the per-request MaxSize limit.…
Check whether github.com/forceu/gokapi is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/forceu/gokapi CVEs against the assets you own.
Start Free Scan →