Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.
History

Wed, 12 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Charmbracelet
Charmbracelet soft-serve
Vendors & Products Charmbracelet
Charmbracelet soft-serve

Mon, 10 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
Description Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.
Title Soft Serve is vulnerable to SSRF through its Webhooks
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-10T22:11:18.863Z

Updated: 2025-11-12T20:13:12.894Z

Reserved: 2025-11-05T21:15:39.401Z

Link: CVE-2025-64522

cve-icon Vulnrichment

Updated: 2025-11-12T17:34:19.207Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-10T23:15:41.987

Modified: 2025-11-12T21:15:54.590

Link: CVE-2025-64522

cve-icon Redhat

No data.