CVE 7.7 HIGH

Soft Serve is vulnerable to arbitrary file writing through its SSH API_CVE-2025-58355

7.7 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Description

Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled data through its SSH API. This issue is fixed in version 0.10.0.

Basic Information

ID CVE-2025-58355
Source GitHub_M
Published Sep 3, 2025 at 23:52

Affected Product

Vendor charmbracelet
Product soft-serve
Version < 0.10.0
Affected Versions charmbracelet soft-serve < 0.10.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.