Gokapi has Data Leak in Upload Status Stream
Package
Affected versions
< 2.2.3
Patched versions
2.2.3
Description
Published to the GitHub Advisory Database
Mar 5, 2026
Reviewed
Mar 5, 2026
Published by the National Vulnerability Database
Mar 6, 2026
Last updated
Mar 8, 2026
Description
The upload status SSE implementation on
/uploadStatuspublishes global upload state to any authenticated listener and includesfile_idvalues that are not scoped to the requesting user.Impact
Any authenticated user can observe other users' file identifiers and retrieve unauthorized content, causing cross-tenant data exposure and loss of confidentiality for uploaded documents.
Issue found by aisafe.io
References