CVE-2026-91773: Soft Serve 0.7.1 through 0.11.6 Information Disclosure via LFS Locks
Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate lock IDs globally to recover locked file paths, usernames, and lock timestamps from private repositories.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Soft Serve user with write access to any repository can exploit it. The user does not need access to the private repositories whose lock metadata is exposed.
What information can be disclosed?
An attacker can enumerate Git LFS lock IDs globally and recover locked file paths, usernames, and lock timestamps from private repositories.
Are installations affected by default?
The issue affects Soft Serve versions 0.7.1 through 0.11.6 where Git LFS lock queries are available. Exploitation requires an authenticated account with write access to at least one repository.