Junglewise Threat Intelligence

CVE-2026-91773: Soft Serve Git LFS lock metadata disclosure

CVE-2026-91773 · Severity: medium · CVSS 4.3 · Published 2026-09-15

Executive brief

Soft Serve is a self-hosted Git server. A flaw in its Git LFS lock functionality allows authenticated users to enumerate and read lock metadata (file paths, usernames, timestamps) from repositories they should not have access to, simply by having write access to any repository on the server. This could expose sensitive information about locked files and repository activities in private repositories.

Technical details

The vulnerability is an authorization bypass in Git LFS lock queries. Soft Serve versions 0.7.1 through 0.11.6 fail to properly scope lock queries by repository, allowing authenticated users with write access to enumerate lock IDs globally across the server. By querying locks without proper repository access checks, attackers can retrieve sensitive lock metadata (locked file paths, lock owner usernames, and lock timestamps) from private repositories they cannot otherwise access. The vulnerability requires an authenticated account with write access to at least one repository; no patch status is explicitly mentioned but a fixed version after 0.11.6 is implied.

Affected products

  • Charm Bracelet Soft Serve 0.7.1 through 0.11.6

Timeline

  • 2026-09-15: disclosed

References