goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6. | |
| Title | Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T19:43:36.037Z
Reserved: 2026-04-15T16:37:22.767Z
Link: CVE-2026-40903
No data.
Status : Received
Published: 2026-04-21T20:17:02.947
Modified: 2026-04-21T20:17:02.947
Link: CVE-2026-40903
No data.
OpenCVE Enrichment
Updated: 2026-04-22T05:30:09Z