CVE-2026-28682 Details
Description
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any authenticated listener and includes file_id values that are not scoped to the requesting user. This issue has been patched in version 2.2.3.
A data leak vulnerability has been identified in Gokapi, a self-hosted file sharing server, prior to version 2.2.3. The issue arises in the upload status Server-Sent Events (SSE) implementation on the '/uploadStatus' endpoint, which broadcasts global upload states to all authenticated listeners. This transmission includes 'file_id' values that are not restricted to the user's own uploads. As a result, any authenticated user can access other users' file identifiers and unauthorized content, leading to cross-tenant data exposure and a loss of confidentiality for the affected documents.
Users are advised to update Gokapi to version 2.2.3, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Forceu/Gokapi/releases/tag/v2.2.3 | [email protected] | Release Notes |
| https://github.com/Forceu/Gokapi/security/advisories/GHSA-c36c-7pc2-f2ph | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| forceu gokapi | < 2.2.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | New CVE Received | [email protected] |