PT-2026-72121 · Semaphore · Semaphore

·

CVE-2026-73682

·

Published

2026-08-14

·

Updated

2026-09-10

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Semaphore versions prior to 2.18.20
Description An OS command injection issue exists in the handling of the repository git url variable. Authenticated users with Manager or Owner roles can achieve remote code execution on the server host by crafting a malicious git url value using the --upload-pack= option. This occurs when the server processes repository operations using the default cmd git client.
Recommendations Update Semaphore to version 2.18.20 or later.

Exploit

Fix

RCE

OS Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73682
GHSA-XP7J-H7JC-4W8P
GO-2026-6435

Affected Products

Semaphore