THREAT OPS › Threat News › [GHSA] GHSA-cxvf-gvfq-36w2 (high) — Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
[GHSA] GHSA-cxvf-gvfq-36w2 (high) — Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
GHSA-cxvf-gvfq-36w2 Severity: high CVE: CVE-2026-73293
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
## Summary
Semaphore resolves a project member's effective permissions in `ProjectMiddleware` by looking up a role row whose slug matches the member's assigned role, and overwrites the built-in permission bitmask with that row's value. A member holding the bu
Indicators of compromise
- CVE-2026-73293cve
- https://www.turingpoint.deurl
- jan@turingpoint.deemail
Original source: https://github.com/advisories/GHSA-cxvf-gvfq-36w2