THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xp7j-h7jc-4w8p (critical) — Semaphore U: OS Command Injection

[GHSA] GHSA-xp7j-h7jc-4w8p (critical) — Semaphore U: OS Command Injection

highgithub_advisoriesPublished 2026-09-08

GHSA-xp7j-h7jc-4w8p Severity: critical CVE: CVE-2026-73294

Semaphore U: OS Command Injection

# Summary An OS command injection in repository git_url handling lets any user holding the Manager or Owner role on any project (the normal project-collaborator roles) achieve remote code execution on the Semaphore server host. Using git's --upload-pack=<cmd> option, an attacker runs arbitrary commands.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xp7j-h7jc-4w8p