Authorization Flaw in Soft Serve Git Server by Charmbracelet
CVE-2026-33353
7.1HIGH
What is CVE-2026-33353?
An authorization flaw in the Soft Serve Git server allows authenticated SSH users to clone server-local Git repositories, including private repositories owned by other users. This vulnerability affects versions from 0.6.0 to before 0.11.6. It has been resolved in version 0.11.6, preventing unauthorized access to private repositories.
Affected Version(s)
soft-serve >= 0.6.0, < 0.11.6
