Command Injection Vulnerability in Semaphore UI by Semaphore
CVE-2026-73294
9.9CRITICAL
What is CVE-2026-73294?
A vulnerability in Semaphore UI allows attackers to inject arbitrary OS commands through manipulated Git repository URL handling. This affects project Managers or Owners who may unknowingly trigger command execution on the server during repository polling or API requests. Users are encouraged to update to versions 2.18.17 or 2.19.5-beta2 for protection from this exploit.
Affected Version(s)
semaphore < 2.18.17 < 2.18.17
semaphore >= 2.19.0-alpha3, < 2.19.5-beta2 < 2.19.0-alpha3, 2.19.5-beta2
