CVE-2026-33353

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*

History

17 Jun 2026, 10:37

Type Values Removed Values Added
Summary
  • (es) Soft Serve es un servidor Git autoalojable para la línea de comandos. Desde la versión 0.6.0 hasta antes de la versión 0.11.6, una falla de autorización en la importación de repositorios permite a cualquier usuario SSH autenticado clonar un repositorio Git local del servidor, incluyendo el repositorio privado de otro usuario, en un nuevo repositorio que ellos controlan. Este problema ha sido parcheado en la versión 0.11.6.

25 Mar 2026, 21:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/charmbracelet/soft-serve/commit/c147421caf234bcfc1570c79d728ecbbe5813e55 - () https://github.com/charmbracelet/soft-serve/commit/c147421caf234bcfc1570c79d728ecbbe5813e55 - Patch
References () https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.6 - () https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.6 - Product, Release Notes
References () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp - () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp - Exploit, Vendor Advisory
First Time Charm
Charm soft Serve
CPE cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*

25 Mar 2026, 14:16

Type Values Removed Values Added
References () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp - () https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp -

24 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 20:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33353

Mitre link : CVE-2026-33353

CVE.ORG link : CVE-2026-33353


JSON object : View

Products Affected

charm

  • soft_serve
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-862

Missing Authorization