CVE-2026-33353

Severity CVSS v4.0:
HIGH
Type:
CWE-200 Information Leak / Disclosure
Publication date:
24/03/2026
Last modified:
25/03/2026

Description

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:* 0.6.0 (including) 0.11.6 (excluding)