PT-2026-71145 · Unknown · Semaphore Ui

CVE-2026-73294

·

Published

2026-08-12

·

Updated

2026-09-10

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Semaphore UI versions prior to 2.18.17 Semaphore UI versions prior to 2.19.5-beta2
Description Improper handling of the git url variable allows a project Manager or Owner to execute arbitrary OS commands within the server process. This occurs when the application passes an attacker-controlled --upload-pack option to the CmdGitClient.GetLastRemoteCommitHash() function via the 'POST /api/project/{id}/repositories' endpoint and during scheduled commit-hash polling.
Recommendations Update to version 2.18.17 or later. Update to version 2.19.5-beta2 or later.

Exploit

Fix

OS Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73294
GHSA-XP7J-H7JC-4W8P
GO-2026-6435

Affected Products

Semaphore Ui