PT-2025-4367 · Unknown+1 · Soft Serve+1
Aymanbagabas
·
Published
2025-01-08
·
Updated
2025-09-05
·
CVE-2025-22130
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Soft Serve versions prior to 0.8.2
Description
Soft Serve is a self-hostable Git server for the command line. A path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user can modify, delete, and access repositories arbitrarily as if they were an admin user without explicitly giving them permissions.
Recommendations
For versions prior to 0.8.2, upgrade to version 0.8.2 to patch the vulnerability.
As a temporary workaround for multi-user set-ups, consider disabling repository creation for users until the upgrade is applied.
Single user set-ups are not affected and do not require any action.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soft Serve
Suse