Impact
Soft Serve versions 0.7.1 through 0.11.6 contain an information disclosure flaw identified as CWE-639. Failure to scope Git LFS lock queries by repository enables any authenticated user with write permission to request a lock identifier and receive the locked file path, the username of the owner, and the timestamp, even for private repositories not owned by the requester. This leakage exposes sensitive repository metadata that can aid attackers in further exploitation.
Affected Systems
Charmbracelet Soft Serve 0.7.1 through 0.11.6.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, primarily compromising confidentiality. The EPSS score is below 1%, suggesting a low probability of exploitation at this time. As it is not listed in KEV, no large‑scale exploit is reported. With write access to any repository, an attacker can enumerate lock IDs globally and retrieve lock metadata from private repositories. The vulnerability is linked to CWE-639, exposing repository metadata without proper authorization.
OpenCVE Enrichment