<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Sourcegraph</title>
  <link>https://cvedaily.com/pages/tags/sourcegraph.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sourcegraph.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Sourcegraph</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-41943 – sourcegraph is a code intelligence platform. As a site admin it was possible to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41943</guid>
    <pubDate>Tue, 22 Nov 2022 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41943</strong></p>
  <p>sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41942 – Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a comman...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41942</guid>
    <pubDate>Tue, 22 Nov 2022 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41942</strong></p>
  <p>Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the `/list-gitolite` endpoint. It was possible to send a crafted request to gitserver that would execute commands inside the container…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31155 – Sourcegraph is an opensource code search and navigation engine. In Sourcegraph v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31155</guid>
    <pubDate>Mon, 01 Aug 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31155</strong></p>
  <p>Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’ saved searches, only overwriting them with attacker-controlled searches. The issue is patched in Sourcegraph version 3.41.0.…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31154 – Sourcegraph is an opensource code search and navigation engine. It is possible f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31154</guid>
    <pubDate>Mon, 01 Aug 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31154</strong></p>
  <p>Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the action of the monitor in question. An attacker is not able to read contents of existing code monitors, only override the data. The issue is fixed in Sourcegraph…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29171 – Sourcegraph is a fast and featureful code search and navigation engine. Versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29171</guid>
    <pubDate>Fri, 06 May 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29171</strong></p>
  <p>Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows Sourcegraph site admins to specify a `callsignCommand`, which is used to obtain the Phabricator metadata for a Gitolite repository. An administrator who is able to edit or add a G…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23642 – Sourcegraph is a code search and navigation engine. Sourcegraph prior to version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23642</guid>
    <pubDate>Fri, 18 Feb 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23642</strong></p>
  <p>Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23643 – Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23643</guid>
    <pubDate>Tue, 15 Feb 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23643</strong></p>
  <p>Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity in the Code Monitoring feature where strings in private source code could be guessed by an authenticated but unauthorized actor. This issue affects only the Code Monitoring feature, whereas CVE-2021-43823 also affected saved searches. A successful att…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-43823 – Sourcegraph is a code search and navigation engine. Sourcegraph prior to version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43823</guid>
    <pubDate>Mon, 13 Dec 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-43823</strong></p>
  <p>Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in private source code could be guessed by an authenticated but unauthorized actor. This issue affects the Saved Searches and Code Monitoring features. A successful attack would require an authenticated bad actor to create many Saved Searches or Code Monitor…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-32787 – Sourcegraph is a code search and navigation engine. Sourcegraph before version 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32787</guid>
    <pubDate>Mon, 02 Aug 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-32787</strong></p>
  <p>Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leaks. The site-admin area can be accessed by regular users and all information and features are properly protected except for daily usage statistics and code intelligence uploads and indexes. It is not possible to alter the information, nor interact with any other features in the s…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-12283 – Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12283</guid>
    <pubDate>Thu, 30 Apr 2020 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-12283</strong></p>
  <p>Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12283">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
