Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve
02 / AFFECTED SOFTWARE
Affected packages
35 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.
Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve
### Impact Path traversal attack gives access to existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. ### Patches This is patched in [v0.8.2](https://github.com/charmbracelet/soft-serve/releases/tag/v0.8.2) ### Workarounds Single user set-ups are not affected. This only affects multi-user Soft Serve set-ups that enable repository creation for users. Otherwise, upgrading is necessary to circumvent the attack.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22130.json
- https://github.com/charmbracelet/soft-serve/commit/a8d1bf3f9349c138383b65079b7b8ad97fff78f4
- https://github.com/charmbracelet/soft-serve/releases/tag/v0.8.2
- https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-j4jw-m6xr-fv6c
- https://nvd.nist.gov/vuln/detail/CVE-2025-22130
- https://github.com/charmbracelet/soft-serve