CVE-2026-40903
Received
Received - Intake
ArtiPACKED Vulnerability in goshs Causes GITHUB_TOKEN Leak
Publication date: 2026-04-21
Last updated on: 2026-05-01
Assigner: GitHub, Inc.
Description
Description
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| goshs | goshs | 2.0.0 |
| goshs | goshs | to 2.0.0 (exc) |
| goshs | goshs | 2.0.0 |
| goshs | goshs | 2.0.0 |
| goshs | goshs | 2.0.0 |
| goshs | goshs | 2.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-829 | The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere. |