charmbracelet
- Total products in the ecosystem
- 3
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/19/2026, charmbracelet recorded 1 security vulnerabilities in the last 90 days across 1 products, including 0 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, soft-serve had the most security vulnerabilities in the charmbracelet ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-91773Soft Serve 0.7.1 through 0.11.6 Information Disclosure via LFS Locks | Exploitation statusNot known exploited | FixYes | Affected productsoft-serve | Published09/15/2026 | SeverityMedium |
CVE-2026-41589Wish has SCP Path Traversal that allows arbitrary file read/write | Exploitation statusPublic exploit | FixYes | Affected productwish | Published05/07/2026 | SeverityCritical |
CVE-2026-33353Soft Serve: Authenticated repo import can clone server-local private repositories | Exploitation statusPublic exploit | FixYes | Affected productsoft-serve | Published03/24/2026 | SeverityHigh |
CVE-2026-30832Soft Serve: SSRF via unvalidated LFS endpoint in repo import | Exploitation statusPublic exploit | FixYes | Affected productsoft-serve | Published03/07/2026 | SeverityCritical |
CVE-2026-24058Soft Serve has Critical Authentication Bypass | Exploitation statusNot known exploited | FixYes | Affected productsoft-serve | Published01/22/2026 | SeverityHigh |
CVE-2026-22253Soft Serve is missing an authorization check in LFS lock deletion | Exploitation statusPublic exploit | FixYes | Affected productsoft-serve | Published01/08/2026 | SeverityMedium |
CVE-2025-64522Soft Serve is vulnerable to SSRF through its Webhooks | Exploitation statusPublic exploit | FixNot confirmed | Affected productsoft-serve | Published11/10/2025 | SeverityCritical |
CVE-2025-64494Soft Serve does not sanitize ANSI escape sequences in user input | Exploitation statusNot known exploited | FixYes | Affected productsoft-serve | Published11/08/2025 | SeverityMedium |
CVE-2025-58355Soft Serve is vulnerable to arbitrary file writing through its SSH API | Exploitation statusPublic exploit | FixYes | Affected productsoft-serve | Published09/03/2025 | SeverityHigh |
CVE-2025-22130Soft Serve allows path traversal attacks | Exploitation statusNot known exploited | FixYes | Affected productsoft-serve | Published01/08/2025 | SeverityMedium |
CVE-2024-41956Soft Serve allows arbitrary code execution by crafting git-lfs requests | Exploitation statusNot known exploited | FixYes | Affected productsoft-serve | Published08/01/2024 | SeverityHigh |
CVE-2023-43809Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled | Exploitation statusPublic exploit | FixNot confirmed | Affected productsoft-serve | Published10/04/2023 | SeverityHigh |
CVE-2022-29180Charm vulnerable to server-side request forgery (SSRF) | Exploitation statusNot known exploited | FixNot confirmed | Affected productcharm | Published05/07/2022 | SeverityMedium |