CVE-2026-33353

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*

History

25 Mar 2026, 21:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/charmbracelet/soft-serve/commit/c147421caf234bcfc1570c79d728ecbbe5813e55 - () https://github.com/charmbracelet/soft-serve/commit/c147421caf234bcfc1570c79d728ecbbe5813e55 - Patch
References () https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.6 - () https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.6 - Product, Release Notes
References () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp - () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp - Exploit, Vendor Advisory
First Time Charm
Charm soft Serve
CPE cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*

25 Mar 2026, 14:16

Type Values Removed Values Added
References () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp - () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp -

24 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 20:16

Updated : 2026-03-25 21:59


NVD link : CVE-2026-33353

Mitre link : CVE-2026-33353

CVE.ORG link : CVE-2026-33353


JSON object : View

Products Affected

charm

  • soft_serve
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-862

Missing Authorization