Home

Description

Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled data through its SSH API. This issue is fixed in version 0.10.0.

PUBLISHED Reserved 2025-08-29 | Published 2025-09-03 | Updated 2025-09-04 | Assigner GitHub_M




HIGH: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Problem types

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

< 0.10.0
affected

References

github.com/...-serve/security/advisories/GHSA-33pr-m977-5w97

cve.org (CVE-2025-58355)

nvd.nist.gov (CVE-2025-58355)

Download JSON