blob: 20fd8006a53c3a1c59528b22d4f952b3f142ea08 [file] [edit]
id: GO-2026-4788
modules:
- module: github.com/charmbracelet/soft-serve
versions:
- introduced: 0.6.0
- fixed: 0.11.6
vulnerable_at: 0.11.5
summary: |-
In Soft Serve, an authenticated repo import can clone server-local private
repositories in github.com/charmbracelet/soft-serve
cves:
- CVE-2026-33353
ghsas:
- GHSA-xgxp-f695-6vrp
references:
- advisory: https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xgxp-f695-6vrp
source:
id: GHSA-xgxp-f695-6vrp
created: 2026-03-23T12:48:40.372026102-04:00
review_status: UNREVIEWED