PT-2026-2184 · Unknown · Soft Serve

·

CVE-2026-22253

·

Published

2026-01-08

·

Updated

2026-07-30

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Soft Serve versions prior to 0.11.2
Description Soft Serve is a self-hostable Git server for the command line. An authorization bypass exists in the LFS lock deletion endpoint. Any authenticated user with repository write access can delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation. The vulnerable endpoint is '/lfs/locks/{lock id}/delete'.
Recommendations Versions prior to 0.11.2 should be updated to version 0.11.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22253
GHSA-6JM8-X3G6-R33J
GO-2026-4290
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0142-1

Affected Products

Soft Serve