A vulnerability marked as problematic has been reported in goshs-labs goshs up to 2.1.0. Affected is an unknown function of the file httpserver/updown.go of the component BulkDownload Handler. This manipulation of the argument File causes information disclosure.

This vulnerability is handled as CVE-2026-54719. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.