CVE 4.6 MEDIUM

Soft Serve does not sanitize ANSI escape sequences in user input_CVE-2025-64494

4.6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Description

Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.

Basic Information

ID CVE-2025-64494
Source GitHub_M
Published Nov 8, 2025 at 01:19

Affected Product

Vendor charmbracelet
Product soft-serve
Version <= 0.10.0
Affected Versions charmbracelet soft-serve <= 0.10.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.