Gokapi has privilege escalation with auth token
Description
Published to the GitHub Advisory Database
Mar 5, 2026
Reviewed
Mar 5, 2026
Published by the National Vulnerability Database
Mar 6, 2026
Last updated
Mar 6, 2026
Impact
A registered user without privileges to create or modify file requests is able to create a short-lived API key that has the permission to do so.
The user must be registered with Gokapi. If you do not have any other users with access to the admin/upload menu, you are not impacted.
Patches
This CVE is patched in v2.2.3
References