OS Command Injection Vulnerability in Semaphore by Semaphore UI
CVE-2026-73682
8.7HIGH
What is CVE-2026-73682?
Semaphore versions before 2.18.20 exhibit a vulnerability that allows authenticated users with Manager or Owner roles to perform OS command injection through the repository git_url handling. By crafting a malicious git_url employing the git's --upload-pack= option, an attacker can inject and execute arbitrary shell commands on the Semaphore server host. This exploitation occurs when the default cmd_git client processes repository operations, potentially allowing for significant unauthorized actions on the server.
Affected Version(s)
semaphore 0
