A registered user without privileges to create or modify file requests is able to create a short-lived API key that has the permission to do so.
The user must be registered with Gokapi. If you do not have any other users with access to the admin/upload menu, you are not impacted.
This CVE is patched in v2.2.3
{
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-05T18:57:18Z",
"nvd_published_at": "2026-03-06T05:16:40Z",
"severity": "MODERATE"
}