CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-22130: Soft Serve allows path traversal attacks

5.3 CVSS

Description

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.

Classification

CVE ID: CVE-2025-22130

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

Affected Products

Vendor: charmbracelet

Product: soft-serve

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.83% (scored less or equal to compared to others)

EPSS Date: 2025-02-06 (when was this score calculated)

References

https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-j4jw-m6xr-fv6c
https://github.com/charmbracelet/soft-serve/commit/a8d1bf3f9349c138383b65079b7b8ad97fff78f4
https://github.com/charmbracelet/soft-serve/releases/tag/v0.8.2

Timeline