github.com/charmbracelet/soft-serve
The mighty, self-hostable Git server for the command line🍦
Activity
- Latest release
- 9h ago
- Total releases
- 51
- Cadence
- ~17 days
- Last 12 months
- 8
Reach
- Stars
- 7.1k
Details
- First release
- Dec 07, 2021
| Version | Released | |
|---|---|---|
v0.12.0
minor
|
v0.12.0
minor
Dependencies (42)
+ 34 more |
|
v0.11.6
patch
|
v0.11.6
patch
Dependencies (42)
+ 34 more |
|
v0.11.5
patch
1 CVE
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev |
v0.11.5
patch
Dependencies (42)
+ 34 more |
|
v0.11.4
patch
1 CVE
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev |
v0.11.4
patch
Dependencies (42)
+ 34 more |
|
v0.11.3
patch
2 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.11.3
patch
Dependencies (42)
+ 34 more |
|
v0.11.2
patch
3 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.11.2
patch
Dependencies (42)
+ 34 more |
|
v0.11.1
patch
4 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.11.1
patch
Dependencies (42)
+ 34 more |
|
v0.11.0
minor
5 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.11.0
minor
Dependencies (42)
+ 34 more |
|
v0.10.0
minor
6 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.10.0
minor
Dependencies (42)
+ 34 more |
|
v0.9.1
patch
7 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.9.1
patch
Dependencies (42)
+ 34 more |
|
v0.9.0
minor
7 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.9.0
minor
Dependencies (42)
+ 34 more |
|
v0.8.5
patch
7 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.5
patch
Dependencies (41)
+ 33 more |
|
v0.8.4
patch
7 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.4
patch
Dependencies (41)
+ 33 more |
|
v0.8.3
patch
7 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.3
patch
Dependencies (41)
+ 33 more |
|
v0.8.2
patch
7 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.2
patch
Dependencies (41)
+ 33 more |
|
v0.8.1
patch
8 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.1
patch
Dependencies (42)
+ 34 more |
|
v0.8.0
minor
8 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.0
minor
Dependencies (42)
+ 34 more |
|
v0.7.6
patch
8 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.6
patch
Dependencies (42)
+ 34 more |
|
v0.7.4
patch
9 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.4
patch
Dependencies (43)
+ 35 more |
|
v0.7.3
patch
9 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.3
patch
Dependencies (43)
+ 35 more |
|
v0.7.2
patch
9 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.2
patch
Dependencies (43)
+ 35 more |
|
v0.7.1
patch
9 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.1
patch
Dependencies (43)
+ 35 more |
|
v0.7.0
minor
9 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (43)
+ 35 more |
|
v0.6.2
patch
9 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.2
patch
Dependencies (41)
+ 33 more |
|
v0.6.1
patch
10 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.1
patch
Dependencies (41)
+ 33 more |
|
v0.6.0
minor
10 CVEs
CVE-2026-33353
GO-2026-4788
GHSA-xgxp-f695-6vrp
Mar 23, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve Fixed in
0.11.6
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30832
GO-2026-4634
GHSA-3fvx-xrxq-8jvv
Mar 10, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve Fixed in
0.11.4
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (41)
+ 33 more |
|
v0.5.4
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.4
patch
Dependencies (32)
+ 24 more |
|
v0.5.3
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.3
patch
Dependencies (32)
+ 24 more |
|
v0.5.2
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.2
patch
Dependencies (30)
+ 22 more |
|
v0.5.1
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.1
patch
Dependencies (30)
+ 22 more |
|
v0.5.0
minor
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (30)
+ 22 more |
|
v0.4.7
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.7
patch
Dependencies (27)
+ 19 more |
|
v0.4.6
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.6
patch
Dependencies (27)
+ 19 more |
|
v0.4.5
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.5
patch
Dependencies (26)
+ 18 more |
|
v0.4.4
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.4
patch
Dependencies (26)
+ 18 more |
|
v0.4.3
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.3
patch
Dependencies (26)
+ 18 more |
|
v0.4.2
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.2
patch
Dependencies (26)
+ 18 more |
|
v0.4.1
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (26)
+ 18 more |
|
v0.4.0
minor
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (26)
+ 18 more |
|
v0.3.3
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.3
patch
Dependencies (24)
+ 16 more |
|
v0.3.2
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.2
patch
Dependencies (24)
+ 16 more |
|
v0.3.1
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.1
patch
Dependencies (24)
+ 16 more |
|
v0.3.0
minor
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (24)
+ 16 more |
|
v0.2.3
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.2.3
patch
Dependencies (18)
+ 10 more |
|
v0.2.2
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.2.2
patch
Dependencies (18)
+ 10 more |
|
v0.2.0
minor
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (18)
+ 10 more |
|
v0.2.1
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.2.1
patch
Dependencies (18)
+ 10 more |
|
v0.1.3
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.1.3
patch
Dependencies (12)
+ 4 more |
|
v0.1.2
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.1.2
patch
Dependencies (12)
+ 4 more |
|
v0.1.1
patch
8 CVEs
CVE-2026-24058
GO-2026-4353
GHSA-pchf-49fh-w34r
Feb 02, 2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve Fixed in
0.11.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22253
GO-2026-4290
GHSA-6jm8-x3g6-r33j
Jan 12, 2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve Fixed in
0.11.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64494
GO-2025-4106
GHSA-fv2r-r8mp-pg48
Nov 17, 2025
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve Fixed in
0.11.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64522
GO-2025-4111
GHSA-vwq2-jx9q-9h9f
Nov 17, 2025
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve Fixed in
0.11.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58355
GO-2025-3930
GHSA-33pr-m977-5w97
Sep 08, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve Fixed in
0.10.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22130
GO-2025-3374
GHSA-j4jw-m6xr-fv6c
Jan 08, 2025
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve Fixed in
0.8.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-43809
GO-2023-2097
GHSA-mc97-99j4-vm2v
Aug 21, 2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve Fixed in
0.6.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41956
GO-2024-3019
GHSA-m445-w3xr-vp2f
Aug 06, 2024
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve Fixed in
0.7.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.1.1
patch
Dependencies (12)
+ 4 more |