CVE-2026-73682: Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling
Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository giturl handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious giturl value using git's --upload-pack= option to inject and execute arbitrary shell commands when the server processes repository operations using the default cmdgit client.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Semaphoreto a version that resolves this vulnerability.Fixed in 2.18.20 - Compensating control
Until upgraded to Semaphore 2.18.20, restrict authenticated users with Manager or Owner roles on projects so they cannot trigger repository operations that process the git_url value handled by the default cmd_git client.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73682?
The severity of CVE-2026-73682 is high with a score of 8.8.
How do I fix CVE-2026-73682?
To fix CVE-2026-73682, upgrade Semaphore to version 2.18.20 or later.
What types of users are affected by CVE-2026-73682?
Authenticated users with Manager or Owner roles on any project are affected by CVE-2026-73682.
What kind of attack can be executed using CVE-2026-73682?
CVE-2026-73682 allows for remote code execution on the Semaphore server host.
Which Semaphore versions are vulnerable to CVE-2026-73682?
Semaphore versions prior to 2.18.20 are vulnerable to CVE-2026-73682.