Security Advisory

CVE-2026-30832

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-07 15:57:39
Last updated 2026-03-09 18:26:21
Assigner GitHub_M
State PUBLISHED

Description

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is blind (the response from a metadata endpoint wont parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at internal targets. This issue has been patched in version 0.11.4.