PT-2026-2184 · Unknown · Soft Serve

Tomer-Pl

·

Published

2026-01-08

·

Updated

2026-01-17

·

CVE-2026-22253

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Soft Serve versions prior to 0.11.2
Description Soft Serve is a self-hostable Git server for the command line. An authorization bypass exists in the LFS lock deletion endpoint. Any authenticated user with repository write access can delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation. The vulnerable endpoint is '/lfs/locks/{lock id}/delete'.
Recommendations Versions prior to 0.11.2 should be updated to version 0.11.2 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-22253
GHSA-6JM8-X3G6-R33J
GO-2026-4290
SUSE-SU-2026:0142-1

Affected Products

Soft Serve