PT-2025-4367 · Unknown+1 · Soft Serve+1

Aymanbagabas

·

Published

2025-01-08

·

Updated

2025-09-05

·

CVE-2025-22130

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Soft Serve versions prior to 0.8.2
Description Soft Serve is a self-hostable Git server for the command line. A path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user can modify, delete, and access repositories arbitrarily as if they were an admin user without explicitly giving them permissions.
Recommendations For versions prior to 0.8.2, upgrade to version 0.8.2 to patch the vulnerability. As a temporary workaround for multi-user set-ups, consider disabling repository creation for users until the upgrade is applied. Single user set-ups are not affected and do not require any action.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22130
GHSA-J4JW-M6XR-FV6C
GO-2025-3374
OPENSUSE-SU-2025:14624-1
OPENSUSE-SU-2025_0060-1
SUSE-SU-2025:0060-1

Affected Products

Soft Serve
Suse