GHSA-3fvx-xrxq-8jvv · Severity: critical · Ecosystem: go — soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is blind (the response from a metadata endpoint won't parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at internal targets. This issue has been patched in version 0.11.4.
Conclusion & alert: CVE-2026-30832 is rated Exploit Available (55/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-08 | — | 0.04% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.1 | 5.3 | [email protected] |
GHSA-3fvx-xrxq-8jvv · Severity: critical · Ecosystem: go — soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| charm | soft_serve | >= 0.6.0, < 0.11.4 | cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:* |
| URL | Tags |
|---|---|
| https://github.com/charmbracelet/soft-serve/commit/3ef660098ab37a7950457da8ecc25b516e37ce4e | Patch |
| https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.4 | Product Release Notes |
| https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-3fvx-xrxq-8jvv | Exploit Mitigation Vendor Advisory |