{"id":"CVE-2025-64522","aliases":["GHSA-vwq2-jx9q-9h9f","GO-2025-4111"],"url":"https://o3.security/vulnerability/CVE-2025-64522","summary":"Soft Serve is vulnerable to SSRF through its Webhooks","details":"Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.","published":"2025-11-10T22:11:18.863Z","modified":"2026-08-12T03:51:39.928965410Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"},"epss":{"score":0.00343,"percentile":0.27686,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/charmbracelet/soft-serve","fixedVersion":"0.11.1"}],"fix":{"url":"https://github.com/charmbracelet/soft-serve/commit/bb73b9a0eea0d902da4811420535842a4f9aae3b","label":"charmbracelet/soft-serve@bb73b9a"},"references":[{"type":"WEB","url":"https://github.com/charmbracelet/soft-serve/releases/tag/v0.11.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64522.json"},{"type":"ADVISORY","url":"https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-vwq2-jx9q-9h9f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64522"},{"type":"FIX","url":"https://github.com/charmbracelet/soft-serve/commit/bb73b9a0eea0d902da4811420535842a4f9aae3b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:39.928965410Z"}}