blob: 84980ec4c8bc7689f7466443b904e566fd0613fb [file] [log] [blame]
id: GO-2025-3374
modules:
- module: github.com/charmbracelet/soft-serve
versions:
- fixed: 0.8.2
vulnerable_at: 0.8.1
summary: Soft Serve vulnerable to path traversal attacks in github.com/charmbracelet/soft-serve
cves:
- CVE-2025-22130
ghsas:
- GHSA-j4jw-m6xr-fv6c
references:
- advisory: https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-j4jw-m6xr-fv6c
- fix: https://github.com/charmbracelet/soft-serve/commit/a8d1bf3f9349c138383b65079b7b8ad97fff78f4
- web: https://github.com/charmbracelet/soft-serve/releases/tag/v0.8.2
source:
id: GHSA-j4jw-m6xr-fv6c
created: 2025-01-08T08:41:22.954732-10:00
review_status: UNREVIEWED