CVE-2026-33353 identifies an authorization flaw in Soft Serve Git server versions 0.6.0 through 0.11.5, enabling an authenticated SSH user to clone any server-local Git repository, including private ones, into a new repository they control. This vulnerability is rated Medium with a CVSS score of 6.5, indicating a network attack vector and low attack complexity, requiring low privileges to achieve high confidentiality impact by exposing sensitive repository data. Currently, there is no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.6.0, < 0.11.6CPE matchmatch criteria | cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.