Home

Description

Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.

PUBLISHED Reserved 2025-11-05 | Published 2025-11-08 | Updated 2025-11-08 | Assigner GitHub_M




MEDIUM: 4.6CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Problem types

CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences

Product status

<= 0.10.0
affected

References

github.com/...-serve/security/advisories/GHSA-fv2r-r8mp-pg48

github.com/...ommit/d9639320b8d0ccd76fe6836a042c042b0ebde549

cve.org (CVE-2025-64494)

nvd.nist.gov (CVE-2025-64494)

Download JSON