Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-73294: Semaphore UI: Malicious Git Commands Can Be Run
CVE-2026-73294 · published 20 days ago
Summary
Semaphore UI's web interface for managing DevOps tools has a security issue that allows a malicious user to run arbitrary system commands on the server. This could potentially allow an attacker to access or modify sensitive data. To fix this issue, update Semaphore UI to version 2.18.17 or 2.19.5-beta2 or later.
What to do
- Update semaphoreui semaphore to version 2.18.20 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| semaphoreui | semaphore |
< 2.18.17 < 2.18.20 |
Original advisory text
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub
References
- https://github.com/semaphoreui/semaphore/commit/7e8a9434bd81b82cf42220151c74801e...
- https://github.com/semaphoreui/semaphore/commit/a7a7a33a64aea382a0726b3722856f29...
- https://github.com/semaphoreui/semaphore/security/advisories/GHSA-xp7j-h7jc-4w8p
- https://github.com/semaphoreui/semaphore/tree/v2.18.17
- https://github.com/semaphoreui/semaphore/tree/v2.19.5-beta2
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73682... Vendor Advisory
- https://github.com/semaphoreui/semaphore Product
- https://github.com/semaphoreui/semaphore/commit/5d87656a680600125fe78edec1f7a0d1... Patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-73682 Vendor Advisory
- https://www.vulncheck.com/advisories/semaphore-prior-to-version-os-command-injec... Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73294... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73294 Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published14 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Monitor software like this
Free during beta