CVE-2026-91773

Source
https://cve.org/CVERecord?id=CVE-2026-91773
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91773.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91773
Aliases
  • GHSA-xqg9-4q65-m2wf
Published
2026-09-15T01:20:34Z
Modified
2026-09-18T03:30:41Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Soft Serve 0.7.1 through 0.11.6 Information Disclosure via LFS Locks
Details

Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate lock IDs globally to recover locked file paths, usernames, and lock timestamps from private repositories.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91773.json"
}
References

Affected packages

Git / github.com/charmbracelet/soft-serve

Affected ranges

Type
GIT
Repo
https://github.com/charmbracelet/soft-serve
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.7.1"
        },
        {
            "fixed": "0.12.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.10.0
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.11.6
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.9.0
v0.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91773.json"