Sourcegraph is a code-search and intelligence platform that, despite maintaining a focused product portfolio, occupies a prominent position in software development infrastructure where it indexes and provides access to enterprise codebases. Its vulnerabilities cluster around information disclosure, code injection, authorization flaws, and configuration-control weaknesses that reflect the platform's deep access to source code and its role in the developer workflow; the product's ability to acquire public exploit code has been moderate across its disclosure history. Defenders should treat Sourcegraph instances as a sensitive asset in their development infrastructure and prioritize patching to prevent unauthorized access to indexed source repositories; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sourcegraph over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23642HIGH Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git e | Feb 18, 2022 | 8.8 | 84 | NO | YES |
CVE-2022-41942HIGH Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. | Nov 22, 2022 | 7.8 | 26 | NO | NO |
CVE-2023-46248HIGH Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain conditio | Oct 31, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-41943HIGH sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. | Nov 22, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-29171HIGH Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code h | May 6, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-23643MEDIUM Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity in the Code Monitoring feature w | Feb 15, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-43823MEDIUM Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in private source code could be guessed | Dec 13, 2021 | 6.5 | 22 | NO | NO |
CVE-2022-31155MEDIUM Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a | Aug 1, 2022 | 4.3 | 17 | NO | NO |
CVE-2022-31154MEDIUM Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. | Aug 1, 2022 | 4.3 | 17 | NO | NO |
CVE-2021-32787MEDIUM Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leaks. The site-admin area can be accessed by regular users and | Aug 2, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sourcegraph.
Media articles that mention a CVE ID that affects a product developed by Sourcegraph — matched by CVE ID, not by vendor name.