Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vwq2-jx9q-9h9f | Soft Serve is vulnerable to SSRF through its Webhooks |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Charmbracelet
Charmbracelet soft-serve |
|
| Vendors & Products |
Charmbracelet
Charmbracelet soft-serve |
Mon, 10 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability. | |
| Title | Soft Serve is vulnerable to SSRF through its Webhooks | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-10T22:11:18.863Z
Reserved: 2025-11-05T21:15:39.401Z
Link: CVE-2025-64522
No data.
Status : Awaiting Analysis
Published: 2025-11-10T23:15:41.987
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-64522
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:48:09Z
Github GHSA