Input Validation Vulnerability in Soft Serve Git Server by Charmbracelet
CVE-2025-64494

4.6MEDIUM

Key Information:

Vendor
CVE Published:
8 November 2025

What is CVE-2025-64494?

Soft Serve, a self-hostable Git server, contains an input validation vulnerability in versions prior to 0.10.0. This flaw allows users to insert unfiltered data, such as names and git messages, which can include ANSI escape sequences. These sequences may be exploited to produce misleading alerts or other deceptive outputs when rendered. The issue has been addressed in version 0.10.0, where proper sanitization of user inputs has been implemented to mitigate risks.

Affected Version(s)

soft-serve <= 0.10.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64494 : Input Validation Vulnerability in Soft Serve Git Server by Charmbracelet