Description
Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.
Published: 2025-11-08
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fv2r-r8mp-pg48 Soft Serve does not sanitize ANSI escape sequences in user input
History

Mon, 10 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Charmbracelet
Charmbracelet soft-serve
Vendors & Products Charmbracelet
Charmbracelet soft-serve

Sat, 08 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.
Title Soft Serve does not sanitize ANSI escape sequences in user input
Weaknesses CWE-150
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Charmbracelet Soft-serve
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-10T15:11:01.604Z

Reserved: 2025-11-05T19:12:25.103Z

Link: CVE-2025-64494

cve-icon Vulnrichment

Updated: 2025-11-10T15:10:53.687Z

cve-icon NVD

Status : Deferred

Published: 2025-11-08T02:15:35.060

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-64494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-10T09:33:30Z

Weaknesses