CVE-2025-64522

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*

History

31 Dec 2025, 17:54

Type Values Removed Values Added
References () https://github.com/charmbracelet/soft-serve/commit/bb73b9a0eea0d902da4811420535842a4f9aae3b - () https://github.com/charmbracelet/soft-serve/commit/bb73b9a0eea0d902da4811420535842a4f9aae3b - Patch
References () https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.1 - () https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.1 - Release Notes
References () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-vwq2-jx9q-9h9f - () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-vwq2-jx9q-9h9f - Exploit, Vendor Advisory
Summary
  • (es) Soft Serve es un servidor Git autoalojable para la línea de comandos. Las versiones anteriores a la 0.11.1 tienen una vulnerabilidad SSRF donde las URL de los webhooks no son validadas, permitiendo a los administradores del repositorio crear webhooks que apunten a servicios internos, redes privadas y puntos finales de metadatos en la nube. La versión 0.11.1 corrige la vulnerabilidad.
First Time Charm
Charm soft Serve
CPE cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*

12 Nov 2025, 21:15

Type Values Removed Values Added
References () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-vwq2-jx9q-9h9f - () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-vwq2-jx9q-9h9f -

10 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-10 23:15

Updated : 2025-12-31 17:54


NVD link : CVE-2025-64522

Mitre link : CVE-2025-64522

CVE.ORG link : CVE-2025-64522


JSON object : View

Products Affected

charm

  • soft_serve
CWE
CWE-918

Server-Side Request Forgery (SSRF)