PT-2026-2184 · Unknown · Soft Serve

Tomer-Pl

·

Publicado

2026-01-08

·

Atualizado

2026-01-17

·

CVE-2026-22253

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Soft Serve versions prior to 0.11.2
Description Soft Serve is a self-hostable Git server for the command line. An authorization bypass exists in the LFS lock deletion endpoint. Any authenticated user with repository write access can delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation. The vulnerable endpoint is '/lfs/locks/{lock id}/delete'.
Recommendations Versions prior to 0.11.2 should be updated to version 0.11.2 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22253
GHSA-6JM8-X3G6-R33J
GO-2026-4290
SUSE-SU-2026:0142-1

Produtos afetados

Soft Serve