Report: CVE-2026-40903 - Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence - Analysis

Report: CVE-2026-40903 - Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence - Analysis

CVE ID :CVE-2026-40903 Published : April 21, 2026, 8:17 p.m. | 28 minutes ago Description :goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
April 21, 2026