Логотип exploitDog
bind:CVE-2025-64494
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64494

Количество 2

Количество 2

nvd логотип

CVE-2025-64494

3 месяца назад

Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-fv2r-r8mp-pg48

3 месяца назад

Soft Serve does not sanitize ANSI escape sequences in user input

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64494

Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.

CVSS3: 4.6
0%
Низкий
3 месяца назад
github логотип
GHSA-fv2r-r8mp-pg48

Soft Serve does not sanitize ANSI escape sequences in user input

CVSS3: 4.6
0%
Низкий
3 месяца назад

Уязвимостей на страницу