Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fv2r-r8mp-pg48 Soft Serve does not sanitize ANSI escape sequences in user input
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 08 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.
Title Soft Serve does not sanitize ANSI escape sequences in user input
Weaknesses CWE-150
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-08T01:19:01.203Z

Reserved: 2025-11-05T19:12:25.103Z

Link: CVE-2025-64494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-08T02:15:35.060

Modified: 2025-11-08T02:15:35.060

Link: CVE-2025-64494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.