CVE-2026-33353Disclosure(charm / soft_serve)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch charm soft_serve systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • soft_serve

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
soft_serve

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 103-2003-2403-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • evan@evandotsh
    Disclosure

    Today I’m publishing CVE-2026-33353, a high severity (7.1) auth bypass vulnerability in Soft Serve that lets any authenticated user clone other users’ private repositories from the server. Upgrade to 0.11.6 to patch.

    Post summary

    The author publicly announces CVE-2026-33353, an auth‑bypass vulnerability in Soft Serve with a severity of 7.1, and recommends upgrading to version 0.11.6 to remediate it.

    1000061
    50 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33353 Authorization Bypass in Soft Serve Git Server Enables Repository Cloning https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33353

    Post summary

    The text announces CVE‑2026‑33353, highlighting an authorization bypass in Soft Serve Git Server that allows repository cloning, but does not provide PoC, exploit details, or mitigation information.

    0000039
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An authenticated repo import flaw in `Soft Serve` (CVE-2026-33353) may permit cloning of server-local private repositories. Monitor official channels for patch availability. #InfoSec #CodeSecurity #Vulnerability https://www.pulsepatch.io/posts/cve-2026-33353-soft-serve-repo-import-vulnerability

    Post summary

    Soft Serve's CVE-2026-33353 is an authenticated repo import flaw that could allow cloning of private repositories; users should monitor official channels for the upcoming patch.

    0000023
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcharmsoft_serve-go-

Explore more