<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – SonarQube Server (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/sonarqube-server.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sonarqube-server-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – SonarQube Server (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-59844 – SonarQube Server and Cloud is a static analysis solution for continuous code qua...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59844</guid>
    <pubDate>Fri, 26 Sep 2025 17:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59844</strong></p>
  <p>SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper validation. This vulnerability bypasses a previous security fix and allows arbitra…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58178 – SonarQube Server and Cloud is a static analysis solution for continuous code qua...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58178</guid>
    <pubDate>Tue, 02 Sep 2025 01:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58178</strong></p>
  <p>SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to the action are treated as shell expressions, allowing potential execution of ar…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58178">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
