Security Advisories for github.com/charmbracelet/soft-serve in go
High
5 months ago
In Soft Serve, an authenticated repo import can clone server-local private repositories
go
github.com/charmbracelet/soft-serve
Critical
5 months ago
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import
go
github.com/charmbracelet/soft-serve
High
7 months ago
Soft Serve Affected by an Authentication Bypass
go
github.com/charmbracelet/soft-serve
Moderate
7 months ago
Soft Serve is missing an authorization check in LFS lock deletion
go
github.com/charmbracelet/soft-serve
Critical
9 months ago
Soft Serve is vulnerable to SSRF through its Webhooks
go
github.com/charmbracelet/soft-serve
Moderate
9 months ago
Soft Serve does not sanitize ANSI escape sequences in user input
go
github.com/charmbracelet/soft-serve
High
12 months ago
Soft Serve vulnerable to arbitrary file writing through SSH API
go
github.com/charmbracelet/soft-serve
Moderate
over 1 year ago
Soft Serve vulnerable to path traversal attacks
go
github.com/charmbracelet/soft-serve
High
about 2 years ago
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests
go
github.com/charmbracelet/soft-serve
High
almost 3 years ago
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled
go
github.com/charmbracelet/soft-serve