Input Validation Vulnerability in Soft Serve Git Server by Charmbracelet
CVE-2025-64494
4.6MEDIUM
What is CVE-2025-64494?
Soft Serve, a self-hostable Git server, contains an input validation vulnerability in versions prior to 0.10.0. This flaw allows users to insert unfiltered data, such as names and git messages, which can include ANSI escape sequences. These sequences may be exploited to produce misleading alerts or other deceptive outputs when rendered. The issue has been addressed in version 0.10.0, where proper sanitization of user inputs has been implemented to mitigate risks.
Affected Version(s)
soft-serve <= 0.10.0
