THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cxvf-gvfq-36w2 (high) — Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

[GHSA] GHSA-cxvf-gvfq-36w2 (high) — Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

highgithub_advisoriesPublished 2026-09-03

GHSA-cxvf-gvfq-36w2 Severity: high CVE: CVE-2026-73293

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

## Summary

Semaphore resolves a project member's effective permissions in `ProjectMiddleware` by looking up a role row whose slug matches the member's assigned role, and overwrites the built-in permission bitmask with that row's value. A member holding the bu

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cxvf-gvfq-36w2