Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.
References
Configurations
No configuration.
History
12 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-vwq2-jx9q-9h9f - |
10 Nov 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-10 23:15
Updated : 2025-11-12 21:15
NVD link : CVE-2025-64522
Mitre link : CVE-2025-64522
CVE.ORG link : CVE-2025-64522
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
