PT-2026-72121 · Semaphore · Semaphore
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Semaphore versions prior to 2.18.20
Description
An OS command injection issue exists in the handling of the repository
git url variable. Authenticated users with Manager or Owner roles can achieve remote code execution on the server host by crafting a malicious git url value using the --upload-pack= option. This occurs when the server processes repository operations using the default cmd git client.Recommendations
Update Semaphore to version 2.18.20 or later.
Exploit
Fix
RCE
OS Command Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Semaphore