CVE-2026-91773: Authorization Bypass Through User-Controlled Key in charmbracelet soft-serve
Soft Serve versions 0.7.1 through 0.11.6 have an authorization bypass vulnerability where Git LFS lock queries are not properly scoped by repository. This allows authenticated users with write access to any repository to read lock metadata from repositories they should not access, including private ones. Attackers can enumerate lock IDs globally to obtain locked file paths, usernames, and lock timestamps from unauthorized repositories.
AI Analysis
Technical Summary
CVE-2026-91773 is an authorization bypass vulnerability in charmbracelet's Soft Serve affecting versions 0.7.1 through 0.11.6. The flaw arises because Git LFS lock queries are not scoped by repository, enabling authenticated users with write access to any repository to access lock metadata from other repositories they do not have permission to access. This metadata includes locked file paths, usernames, and lock timestamps, potentially exposing sensitive information about private repositories.
Potential Impact
The vulnerability allows unauthorized disclosure of Git LFS lock metadata from private repositories. While it does not grant direct code or data access, it leaks information about locked files and user activity, which could aid further reconnaissance or targeted attacks. The CVSS 4.0 base score is 5.3 (medium severity), reflecting network attack vector, low complexity, and limited impact confined to information disclosure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict write access to trusted users only and monitor repository permissions carefully to limit exposure. Avoid granting unnecessary write permissions to reduce risk.
CVE-2026-91773: Authorization Bypass Through User-Controlled Key in charmbracelet soft-serve
Description
Soft Serve versions 0.7.1 through 0.11.6 have an authorization bypass vulnerability where Git LFS lock queries are not properly scoped by repository. This allows authenticated users with write access to any repository to read lock metadata from repositories they should not access, including private ones. Attackers can enumerate lock IDs globally to obtain locked file paths, usernames, and lock timestamps from unauthorized repositories.
CVSS v4.0
Score 5.3medium
Affected software
charmbracelet
soft-serve
pkg:github/charmbracelet/soft-serveRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-91773 is an authorization bypass vulnerability in charmbracelet's Soft Serve affecting versions 0.7.1 through 0.11.6. The flaw arises because Git LFS lock queries are not scoped by repository, enabling authenticated users with write access to any repository to access lock metadata from other repositories they do not have permission to access. This metadata includes locked file paths, usernames, and lock timestamps, potentially exposing sensitive information about private repositories.
Potential Impact
The vulnerability allows unauthorized disclosure of Git LFS lock metadata from private repositories. While it does not grant direct code or data access, it leaks information about locked files and user activity, which could aid further reconnaissance or targeted attacks. The CVSS 4.0 base score is 5.3 (medium severity), reflecting network attack vector, low complexity, and limited impact confined to information disclosure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict write access to trusted users only and monitor repository permissions carefully to limit exposure. Avoid granting unnecessary write permissions to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-15T00:45:13.102Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa8a72855bf5e2cf5fa7f7f
Added to database: 09/15/2026, 02:02:16 UTC
Last enriched: 09/15/2026, 02:16:39 UTC
Last updated: 09/15/2026, 05:17:30 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.