FlawAtlas
Search the atlas
CVE-2025-22130 Moderate

Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve

Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve

Exploit probability 0.7%
Published January 8, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

35 explicit affected versions

Go github.com/charmbracelet/soft-serve
Go github.com/charmbracelet/soft-serve

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-22130

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.

View original source
Open Source Vulnerabilities GO-2025-3374

Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve

View original source
Open Source Vulnerabilities GHSA-j4jw-m6xr-fv6c

### Impact Path traversal attack gives access to existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. ### Patches This is patched in [v0.8.2](https://github.com/charmbracelet/soft-serve/releases/tag/v0.8.2) ### Workarounds Single user set-ups are not affected. This only affects multi-user Soft Serve set-ups that enable repository creation for users. Otherwise, upgrading is necessary to circumvent the attack.

View original source

05 / REFERENCES

Further evidence