CNNVD-202511-882 Information
Nov 10, 2025
cve
CNNVD ID
CNNVD-202511-882
Related CVE
- CNNVD Published: 2025-11-10
Description (Chinese)
Soft Serve是Charm开源的一个可自托管的命令行 Git 服务器。 Soft Serve 0.11.1之前版本存在代码问题漏洞,该漏洞源于未验证webhook URL,可能导致服务端请求伪造攻击。
Description (English)
Soft Serve is a self-serving command line of Charming open source Git server. There was a code problem loophole in the pre-Soft Server 0.11.1 version, which originated from the unverified webbook URL, which could lead to a request by the service for a forgery attack.
Hazard Level
High
Vulnerability Type
代码问题
Affected Vendor
Charm
Published
2025-11-10
Last Modified
2026-02-24
References
https://github.com/charmbracelet/soft-serve/commit/bb73b9a0eea0d902da4811420535842a4f9aae3b https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.1 https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-vwq2-jx9q-9h9f
Patch
https://github.com/charmbracelet/soft-serve/releases
Share on: