<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Sourcegraph (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/sourcegraph.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sourcegraph-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Sourcegraph (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-41943 – sourcegraph is a code intelligence platform. As a site admin it was possible to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41943</guid>
    <pubDate>Tue, 22 Nov 2022 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41943</strong></p>
  <p>sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41942 – Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a comman...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41942</guid>
    <pubDate>Tue, 22 Nov 2022 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41942</strong></p>
  <p>Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the `/list-gitolite` endpoint. It was possible to send a crafted request to gitserver that would execute commands inside the container…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23642 – Sourcegraph is a code search and navigation engine. Sourcegraph prior to version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23642</guid>
    <pubDate>Fri, 18 Feb 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23642</strong></p>
  <p>Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23642">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
