charm
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 7, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Wish has SCP Path Traversal that allows arbitrary file read/write
Soft Serve: Authenticated repo import can clone server-local private repositories
Soft Serve: SSRF via unvalidated LFS endpoint in repo import
Soft Serve has Critical Authentication Bypass
Soft Serve is missing an authorization check in LFS lock deletion
Soft Serve is vulnerable to SSRF through its Webhooks
Soft Serve allows path traversal attacks
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled
Charm vulnerable to server-side request forgery (SSRF)
Monitor charm in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.