Description
Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate lock IDs globally to recover locked file paths, usernames, and lock timestamps from private repositories.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality compromise
Action: Apply Patch
AI Analysis

Impact

Soft Serve versions 0.7.1 through 0.11.6 contain an information disclosure flaw identified as CWE-639. Failure to scope Git LFS lock queries by repository enables any authenticated user with write permission to request a lock identifier and receive the locked file path, the username of the owner, and the timestamp, even for private repositories not owned by the requester. This leakage exposes sensitive repository metadata that can aid attackers in further exploitation.

Affected Systems

Charmbracelet Soft Serve 0.7.1 through 0.11.6.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, primarily compromising confidentiality. The EPSS score is below 1%, suggesting a low probability of exploitation at this time. As it is not listed in KEV, no large‑scale exploit is reported. With write access to any repository, an attacker can enumerate lock IDs globally and retrieve lock metadata from private repositories. The vulnerability is linked to CWE-639, exposing repository metadata without proper authorization.

Generated by OpenCVE AI on September 17, 2026 at 19:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Soft Serve release that includes the fix for lock visibility errors
  • Restrict write access to repositories to trusted users only, ensuring that only those who should see lock information have those privileges
  • Disable Git LFS locks if the feature is not required, or configure strict repository‑level locking to prevent cross‑repo leakage
  • Monitor and audit lock queries and repository access logs for unusual patterns

Generated by OpenCVE AI on September 17, 2026 at 19:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Charmbracelet
Charmbracelet soft-serve
Vendors & Products Charmbracelet
Charmbracelet soft-serve

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate lock IDs globally to recover locked file paths, usernames, and lock timestamps from private repositories.
Title Soft Serve 0.7.1 through 0.11.6 Information Disclosure via LFS Locks
First Time appeared Charm
Charm soft Serve
Weaknesses CWE-639
CPEs cpe:2.3:a:charm:soft_serve:*:*:*:*:*:*:*:*
Vendors & Products Charm
Charm soft Serve
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Charm Soft Serve
Charmbracelet Soft-serve
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:26.000Z

Reserved: 2026-09-15T00:45:13.102Z

Link: CVE-2026-91773

cve-icon Vulnrichment

Updated: 2026-09-15T19:05:15.507Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T02:16:50.013

Modified: 2026-09-16T19:47:01.197

Link: CVE-2026-91773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key