CVE-2026-73682
Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository giturl handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious giturl value using git's --upload-pack= option to inject and execute arbitrary shell commands when the server processes repository operations using the default cmd_git client.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73682.json, https://nvd.nist.gov/vuln/detail/CVE-2026-73682, https://www.vulncheck.com/advisories/semaphore-prior-to-version-os-command-injection-via-git-url-repository-handling, https://github.com/semaphoreui/semaphore/commit/5d87656a680600125fe78edec1f7a0d10484b52c, https://github.com/semaphoreui/semaphore, https://github.com/semaphoreui/semaphore/security/advisories/GHSA-xp7j-h7jc-4w8p