CVE-2025-64494
Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0.
- Affected products
- Soft Serve
- Fix
- Available
- CVSS 3.1
- 4.6 MEDIUM
- EPSS
- 0.2% (7th percentile)
- Weakness
- CWE-150
- NVD status
- Deferred
- Published
- 2025-11-08
CVE-2025-64494 at NVD
No indexed exploits for CVE-2025-64494 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-64494 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.