THREAT OPS › Threat News › [GHSA] GHSA-8cj9-r88m-8945 (high) — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
[GHSA] GHSA-8cj9-r88m-8945 (high) — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
GHSA-8cj9-r88m-8945 Severity: high CVE: CVE-2026-73292
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
### Summary
The password change form is vulnerable to CSRF, allowing an attacker to change a user password (even the administrator) by tricking a connected user to visit a malicious website. The vulnerability has been tested with version 2.
Indicators of compromise
- CVE-2026-73292cve
- http://semaphore:3000url
- logging.infodomain
Original source: https://github.com/advisories/GHSA-8cj9-r88m-8945