Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26657 | Soft Serve vulnerable to arbitrary file writing through SSH API |
Github GHSA |
GHSA-33pr-m977-5w97 | Soft Serve vulnerable to arbitrary file writing through SSH API |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 04 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Charmbracelet
Charmbracelet soft-serve |
|
| Vendors & Products |
Charmbracelet
Charmbracelet soft-serve |
Thu, 04 Sep 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled data through its SSH API. This issue is fixed in version 0.10.0. | |
| Title | Soft Serve is vulnerable to arbitrary file writing through its SSH API | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-04T14:05:53.888Z
Reserved: 2025-08-29T16:19:59.010Z
Link: CVE-2025-58355
Updated: 2025-09-04T14:05:49.372Z
Status : Awaiting Analysis
Published: 2025-09-04T10:42:32.617
Modified: 2025-09-04T15:35:29.497
Link: CVE-2025-58355
No data.
OpenCVE Enrichment
Updated: 2025-09-04T13:12:14Z
EUVD
Github GHSA