Soft Serve vulnerable to arbitrary file writing through SSH API
Modified: 9/8/2025
package
pkg:go/github.com/charmbracelet/soft-serve
Soft Serve vulnerable to arbitrary file writing through SSH API
Modified: 9/8/2025
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import
Modified: 3/23/2026
Soft Serve is missing an authorization check in LFS lock deletion
Modified: 2/3/2026
Soft Serve does not sanitize ANSI escape sequences in user input
Modified: 11/17/2025
Soft Serve vulnerable to path traversal attacks
Modified: 1/8/2025
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests
Modified: 8/7/2024
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled
Modified: 9/10/2026
Soft Serve Affected by an Authentication Bypass
Modified: 2/3/2026
Soft Serve is vulnerable to SSRF through its Webhooks
Modified: 11/17/2025
In Soft Serve, an authenticated repo import can clone server-local private repositories
Modified: 3/27/2026
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
Soft Serve vulnerable to arbitrary file writing through SSH API in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
Soft Serve does not sanitize ANSI escape sequences in user input in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
Soft Serve is vulnerable to SSRF through its Webhooks in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
Soft Serve is missing an authorization check in LFS lock deletion in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
Soft Serve Affected by an Authentication Bypass in github.com/charmbracelet/soft-serve
Modified: 3/3/2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import in github.com/charmbracelet/soft-serve
Modified: 3/23/2026
In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve
Modified: 3/23/2026