Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.
References
| Link | Resource |
|---|---|
| https://github.com/Forceu/Gokapi/releases/tag/v2.2.4 | Product Release Notes |
| https://github.com/Forceu/Gokapi/security/advisories/GHSA-j6jp-78w8-34x6 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-13 19:54
Updated : 2026-03-17 13:48
NVD link : CVE-2026-30943
Mitre link : CVE-2026-30943
CVE.ORG link : CVE-2026-30943
JSON object : View
Products Affected
forceu
- gokapi
CWE
CWE-863
Incorrect Authorization
