← volver
CVE-2025-22130

Soft Serve allows path traversal attacks

CVSS 5.3 MEDIUMEPSS 0.7%CWE-22
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
charmbracelet · soft-serve

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →