๐Ÿ” CVE Alert

CVE-2026-91773

MEDIUM 4.3

Soft Serve 0.7.1 through 0.11.6 Information Disclosure via LFS Locks

CVSS Score
4.3
EPSS Score
0.2%
EPSS Percentile
10th

Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate lock IDs globally to recover locked file paths, usernames, and lock timestamps from private repositories.

CWE CWE-639
Vendor charmbracelet
Product soft-serve
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for charmbracelet soft-serve

Be the first to know when new medium vulnerabilities affecting charmbracelet soft-serve are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

charmbracelet / soft-serve
0.7.1 < 0.12.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-xqg9-4q65-m2wf github.com: https://github.com/charmbracelet/soft-serve/commit/e34914699128c937afad167d43ccb5310e48b319 github.com: https://github.com/charmbracelet/soft-serve/blob/v0.11.6/pkg/store/database/lfs.go#L115-L124 github.com: https://github.com/charmbracelet/soft-serve vulncheck.com: https://www.vulncheck.com/advisories/soft-serve-0.7.1-through-0.11.6-information-disclosure-via-lfs-locks

Credits

๐Ÿ” sondt99 ๐Ÿ” George Chen