GHSA-mc97-99j4-vm2v

    Dashboard / Vulnerabilities / GHSA-mc97-99j4-vm2v

    GHSA-mc97-99j4-vm2v

    Published: 2 Oct 2023Last Modified: 10 Sept 2026

    Summary: Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled

    Details: ### Impact A security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to bypass public key authentication when keyboard-interactive SSH authentication is active, through the `allow-keyless` setting, and the public key requires additional client-side verification for example using FIDO2 or GPG. This is due to insufficient validation procedures of the public key step during SSH request handshake, granting unauthorized access if the keyboard-interaction mode is utilized. An attacker could exploit this vulnerability by presenting manipulated SSH requests using keyboard-interactive authentication mode. This could potentially result in unauthorized access to the Soft Serve. ### Patches Users should upgrade to the latest Soft Serve version `v0.6.2` to receive the patch for this issue. ### Workarounds To workaround this vulnerability without upgrading, users can _temporarily_ disable Keyboard-Interactive SSH Authentication using the `allow-keyless` setting. ### References https://github.com/charmbracelet/soft-serve/issues/389

    Affected packages

    Package

    Name: github.com/charmbracelet/soft-serve

    Purl: pkg:golang/github.com/charmbracelet/soft-serve

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.6.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-mc97-99j4-vm2v | CVE-DB