Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-64494

Опубликовано: 08 нояб. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.

EPSS

Процентиль: 11%
0.00037
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 4.6
github
3 месяца назад

Soft Serve does not sanitize ANSI escape sequences in user input

EPSS

Процентиль: 11%
0.00037
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-150