CVE-2026-22253
MEDIUMSoft Serve < 0.11.2 - Authenticated Authorization Bypass via LFS Lock Deletion Force Flag
Title source: llmDescription
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2.
References (2)
Core 2
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-6jm8-x3g6-r33j
Scores
CVSS v3
5.4
EPSS
0.0027
EPSS Percentile
18.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
charm/soft_serve
< 0.11.2
charmbracelet/soft-serve
0 - 0.11.2Go
Published
Jan 08, 2026
Tracked Since
Feb 18, 2026