CRITICAL🇵🇱 Wersja polska

CVE-2026-30832

CVSS 9.1v3.1pub. 2026-03-07upd. 2026-03-11

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is blind (the response from a metadata endpoint won't parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at internal targets. This issue has been patched in version 0.11.4.

🤖 AI Analysis
How it works

An attacker uses the repository import command with a properly crafted --lfs-endpoint parameter pointing to a fake LFS server controlled by them. In the first step, the Soft Serve server sends a blind batch request to the provided endpoint (the response is not parsed as valid LFS JSON). Next, the fake LFS server returns a response containing download URLs pointing to internal network resources, and Soft Serve makes subsequent HTTP requests to these internal targets. This way, the attacker gains full read access to responses from internal services.

Impact

An attacker can gain read access to data from internal services and network resources not accessible from the outside (e.g., cloud metadata, internal APIs, databases). The vulnerability also enables disclosure of sensitive information from the server's hosting infrastructure.

Mitigation & patch

Soft Serve should be updated to version 0.11.4, in which the vulnerability has been patched. The patch is available in the official GitHub repository of the charmbracelet/soft-serve project.

Who is affected

Soft Serve (Charm) in versions 0.6.0 through 0.11.3 inclusive. An SSH account with server access is required.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Charm Soft Serve

    APP
    Charm
    0.6.0 – 0.11.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-64522CRITICAL9.1PL ✓same product

SSRF w Soft Serve — webhooks bez walidacji URL umożliwiają dostęp do sieci wewnętrznej

CVE-2026-33353HIGH7.1same product

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an...

CVE-2026-24058HIGH8.1same product

Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authe...

CVE-2023-43809HIGH7.5same product

Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerabilit...

CVE-2026-22253MEDIUM5.4same product

Soft Serve to samodzielnie hostowany serwer Git dla linii poleceń. Przed wersją 0.11.2 błąd autoryzacji w endp...