Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.
History

Mon, 10 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Charmbracelet
Charmbracelet soft-serve
Vendors & Products Charmbracelet
Charmbracelet soft-serve

Sat, 08 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.
Title Soft Serve does not sanitize ANSI escape sequences in user input
Weaknesses CWE-150
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-08T01:19:01.203Z

Updated: 2025-11-10T15:11:01.604Z

Reserved: 2025-11-05T19:12:25.103Z

Link: CVE-2025-64494

cve-icon Vulnrichment

Updated: 2025-11-10T15:10:53.687Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-08T02:15:35.060

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-64494

cve-icon Redhat

No data.