CVE-2026-33353: Charm Soft Serve

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.

Affected products

  • Charm Soft Serve: from 0.6.0, before 0.11.6 (fixed in 0.11.6)

Published 2026-03-24. Last modified 2026-06-17.