Skip to content
archiveexploit · 08 Sep 2026 · 17:57 UTC

GHSA-xp7j-h7jc-4w8p: Semaphore U: OS Command Injection

EXPLCVE-2026-73294source · GTH
HIGHCritical vulnerability — CVSS 9.9
What to do
  • Critical severity — schedule an urgent patch.

last 60 dispatches · spectrum

# Summary An OS command injection in repository git_url handling lets any user holding the Manager or Owner role on any project (the normal project-collaborator roles) achieve remote code execution on the Semaphore server host. Using git's --upload-pack= option, an attacker runs arbitrary commands. The command executes inside the main Semaphore server process (via the schedule commit-hash poller), so it runs even when jobs are configured for remote runners — bypassing runner isolation and exposing the master encryption key and every project's secrets. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected