Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-73682

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Aug 14, 2026
Vendor unknown

Description

Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git's --upload-pack= option to inject and execute arbitrary shell commands when the server processes repository operations using the default cmd_git client.

References