🛡️ CVE-2024-41956 — soft-serve
Description
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests
Impact
Any servers using soft-serve server and git
Patches
>0.7.5
Workarounds
None.
References
n/a.
It is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation and Git.
The issue is that Soft Serve passes all environment variables given by the client to git subprocesses. This includes environment variables that control program execution, such as LD_PRELOAD.
This can be exploited to execute arbitrary code by, for example, uploading a malicious shared object file to Soft Serve via Git LFS (uploading it via LFS ensures that it is not compressed on disk and easier to work with). The file will be stored under its SHA256 hash, so it has a predictable name.
This file can then be referenced in LD_PRELOAD via a Soft Serve SSH session that causes git to be invoked. For example:
```bash
LD_PRELOAD=/.../data/lfs/1/objects/a2/b5/a2b585befededf5f95363d06d83655229e393b1b45f76d9f989a336668665a2f ssh server git-upload-pack repo
```
The example LFS file patches a shared library function called by git to execute a shell.
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability none.
Weakness class
CVE-2024-41956 is classified as CWE-78: OS Command Injection. Untrusted input reaches a shell command without neutralisation, so an attacker can run arbitrary operating system commands.
Affected software
CVE-2024-41956 is recorded against 2 packages.
- github.com/charmbracelet/soft-serve
- unknown
Timeline and source
Published on 2 August 2024 and last revised on 3 March 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.
References
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
pkg.go.dev (Web)
Details
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| github.com/charmbracelet/soft-serve | — | — |
| unknown | — | — |
References
Similar Threats
- High CVE-2026-33353
- Critical CVE-2026-30832
- Critical CVE-2026-24058
- Medium CVE-2026-22253
- Critical CVE-2025-64522
Site Security Check
Is soft-serve part of your stack?
CVE-2024-41956 is rated CVSS 8.1 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.