Browse all 10 CVE security advisories affecting sourcegraph. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Sourcegraph provides code search and AI-powered coding assistance to help developers navigate and understand codebases. Historically, the platform has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and access control issues. While no major public security incidents have been widely reported, the 10 documented CVEs highlight potential risks in web application components and API endpoints. The platform's security posture appears to prioritize rapid feature development, which may occasionally introduce vulnerabilities that require timely patching. Organizations implementing Sourcegraph should maintain regular updates and implement least privilege access controls to mitigate potential exploitation risks.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-41942 | Sourcegraph vulnerable to Comand Injection via gitserver — sourcegraph CWE-20 | 7.9 | High | 2022-11-22 |
| CVE-2022-41943 | Incorrect default permissions found in Sourcegraph — sourcegraph CWE-276 | 9.0 | Critical | 2022-11-22 |
| CVE-2022-31155 | Unauthorized overwriting of saved searches in Sourcegraph — sourcegraph CWE-863 | 4.3 | Medium | 2022-08-01 |
| CVE-2022-31154 | Indirect Object Access in Sourcegraph Code Monitoring — sourcegraph CWE-863 | 6.4 | Medium | 2022-08-01 |
| CVE-2022-29171 | Remote Code Execution in sourcegraph — sourcegraph CWE-74 | 6.6 | Medium | 2022-05-05 |
| CVE-2022-23642 | Code Injection in Sourcegraph — sourcegraph CWE-94 | 8.8 | High | 2022-02-18 |
| CVE-2022-23643 | Side-channel attack in Sourcegraph Code Monitors — sourcegraph CWE-200 | 6.5 | Medium | 2022-02-15 |
| CVE-2021-43823 | Side-channel attack in Sourcegraph — sourcegraph CWE-200 | 6.5 | Medium | 2021-12-13 |
| CVE-2021-32787 | Low risk information disclosure in Sourcegraph — sourcegraph CWE-200 | 3.1 | Low | 2021-08-02 |
This page lists every published CVE security advisory associated with sourcegraph. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.