Sploitus

CVE-2025-64494

No indexed exploits for CVE-2025-64494 yet

Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.

Affected products
Soft Serve
Fix
Available
CVSS 3.1
4.6 MEDIUM
EPSS
0.2% (7th percentile)
Weakness
CWE-150
NVD status
Deferred
Published
2025-11-08
CVE-2025-64494 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-64494 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-64494 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.