Home

Description

Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2.

PUBLISHED Reserved 2026-01-07 | Published 2026-01-08 | Updated 2026-01-08 | Assigner GitHub_M




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Problem types

CWE-863: Incorrect Authorization

Product status

< 0.11.2
affected

References

github.com/...-serve/security/advisories/GHSA-6jm8-x3g6-r33j

github.com/...ommit/000ab5164f0be68cf1ea6b6e7227f11c0e388a42

cve.org (CVE-2026-22253)

nvd.nist.gov (CVE-2026-22253)

Download JSON