Command Injection Vulnerability in Semaphore UI by Semaphore
CVE-2026-73294

9.9CRITICAL

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73294?

A vulnerability in Semaphore UI allows attackers to inject arbitrary OS commands through manipulated Git repository URL handling. This affects project Managers or Owners who may unknowingly trigger command execution on the server during repository polling or API requests. Users are encouraged to update to versions 2.18.17 or 2.19.5-beta2 for protection from this exploit.

Affected Version(s)

semaphore < 2.18.17 < 2.18.17

semaphore >= 2.19.0-alpha3, < 2.19.5-beta2 < 2.19.0-alpha3, 2.19.5-beta2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.