GHSA-xp7j-h7jc-4w8p: Semaphore U: OS Command Injection
HIGHCritical vulnerability — CVSS 9.9
What to do
- Critical severity — schedule an urgent patch.
# Summary An OS command injection in repository git_url handling lets any user holding the Manager or Owner role on any project (the normal project-collaborator roles) achieve remote code execution on the Semaphore server host. Using git's --upload-pack= option, an attacker runs arbitrary commands. The command executes inside the main Semaphore server process (via the schedule commit-hash poller), so it runs even when jobs are configured for remote runners — bypassing runner isolation and exposing the master encryption key and every project's secrets. …
CVE · detail
- CVE-2026-73294nvd ↗EPSS 0.57%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected