Junglewise Threat Intelligence

CVE-2026-33353: GO-2026-4788 - In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve

CVE-2026-33353 · Severity: medium · CVSS 4 · Published 2026-03-23

Technologies: github.com/charmbracelet/soft-serve (Go). Vendors: Go.

Executive brief

In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve

Affected products

  • Go github.com/charmbracelet/soft-serve

Related threats