{"api_version":"v1","generated_at":"2026-10-08T21:30:00+00:00","product":{"cve_count":11,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-charmbracelet-soft-serve-46cc4fe6ae61","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/soft-serve","name":"soft-serve","next_cursor":null,"observations":[{"affected":"soft-serve: 0.7.1 < 0.12.0","affected_versions_present":true,"cve_id":"CVE-2026-91773","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91773","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T14:22:26.000Z","patch_url":"","primary_source":"","published":"2026-09-15T01:20:34.488Z"},{"affected":">= 0.6.0, < 0.11.6","affected_versions_present":true,"cve_id":"CVE-2026-33353","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33353","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-25T13:35:15.415Z","patch_url":"https://github.com/charmbracelet/soft-serve/commit/c147421caf234bcfc1570c79d728ecbbe5813e55","primary_source":"","published":"2026-03-24T19:39:38.331Z"},{"affected":">= 0.6.0, < 0.11.4","affected_versions_present":true,"cve_id":"CVE-2026-30832","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30832","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-09T18:26:21.312Z","patch_url":"https://github.com/charmbracelet/soft-serve/commit/3ef660098ab37a7950457da8ecc25b516e37ce4e","primary_source":"","published":"2026-03-07T15:57:39.158Z"},{"affected":"< 0.11.3","affected_versions_present":true,"cve_id":"CVE-2026-24058","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24058","fixed":"0.11.3.","last_modified":"2026-01-23T20:14:08.759Z","patch_url":"https://github.com/charmbracelet/soft-serve/commit/8539f9ad39918b67d612a35785a2b4326efc8741","primary_source":"","published":"2026-01-22T22:01:22.276Z"},{"affected":"< 0.11.2","affected_versions_present":true,"cve_id":"CVE-2026-22253","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22253","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-08T18:51:14.716Z","patch_url":"https://github.com/charmbracelet/soft-serve/commit/000ab5164f0be68cf1ea6b6e7227f11c0e388a42","primary_source":"","published":"2026-01-08T18:39:57.714Z"},{"affected":"< 0.11.1","affected_versions_present":true,"cve_id":"CVE-2025-64522","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64522","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-12T20:13:12.894Z","patch_url":"https://github.com/charmbracelet/soft-serve/commit/bb73b9a0eea0d902da4811420535842a4f9aae3b","primary_source":"","published":"2025-11-10T22:11:18.863Z"},{"affected":"<= 0.10.0","affected_versions_present":true,"cve_id":"CVE-2025-64494","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64494","fixed":"0.10.0.","last_modified":"2025-11-10T15:11:01.604Z","patch_url":"https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-fv2r-r8mp-pg48","primary_source":"","published":"2025-11-08T01:19:01.203Z"},{"affected":"< 0.10.0","affected_versions_present":true,"cve_id":"CVE-2025-58355","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-58355","fixed":"0.10.0.","last_modified":"2025-09-04T14:05:53.888Z","patch_url":"https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-33pr-m977-5w97","primary_source":"","published":"2025-09-03T23:52:23.555Z"},{"affected":"< 0.8.2","affected_versions_present":true,"cve_id":"CVE-2025-22130","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-22130","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-01-08T19:16:13.209Z","patch_url":"https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-j4jw-m6xr-fv6c","primary_source":"","published":"2025-01-08T15:43:05.244Z"},{"affected":"< 0.7.5","affected_versions_present":true,"cve_id":"CVE-2024-41956","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-41956","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T14:47:38.561Z","patch_url":"","primary_source":"","published":"2024-08-01T22:07:32.899Z"},{"affected":"< 0.6.2","affected_versions_present":true,"cve_id":"CVE-2023-43809","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-43809","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-20T14:51:49.413Z","patch_url":"https://github.com/charmbracelet/soft-serve/commit/407c4ec72d1006cee1ff8c1775e5bcc091c2bc89","primary_source":"","published":"2023-10-04T20:40:41.822Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"charmbracelet"}}
