Vulnerabilities & PatchesEmerging1 src
CVE-2026-73294 - Semaphore U: OS Command Injection
CVE ID : CVE-2026-73294
Published : Aug. 12, 2026, 4:17 p. m.
• 47 minutes ago
Description : Semaphore UI is a web interface for managing DevOps tools. Prior to 2. 18. 17 and 2. 19. 5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient. GetLastRemoteCommitHash through POST /api/project/{id}/repositories and scheduled commit-hash polling, allowing a project Manager or Owner to execute arbitrary OS commands in the Semaphore server process.
This issue is fixed in versions 2. 18. 17 and 2. 19. 5-beta2.
Severity: 9.9
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...