Количество 2
Количество 2
CVE-2026-33353
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.
GHSA-xgxp-f695-6vrp
In Soft Serve, an authenticated repo import can clone server-local private repositories
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33353 Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-xgxp-f695-6vrp In Soft Serve, an authenticated repo import can clone server-local private repositories | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу