Browse all 10 CVE security advisories affecting sourcegraph. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Sourcegraph provides code search and AI-powered coding assistance to help developers navigate and understand codebases. Historically, the platform has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and access control issues. While no major public security incidents have been widely reported, the 10 documented CVEs highlight potential risks in web application components and API endpoints. The platform's security posture appears to prioritize rapid feature development, which may occasionally introduce vulnerabilities that require timely patching. Organizations implementing Sourcegraph should maintain regular updates and implement least privilege access controls to mitigate potential exploitation risks.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-46248 | Overwrite of builtin Cody commands facilitates RCE — cody CWE-15 | 9.1 | Critical | 2023-10-31 |
This page lists every published CVE security advisory associated with sourcegraph. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.