THREAT OPS › Threat News › [GHSA] GHSA-xp7j-h7jc-4w8p (critical) — Semaphore U: OS Command Injection
[GHSA] GHSA-xp7j-h7jc-4w8p (critical) — Semaphore U: OS Command Injection
GHSA-xp7j-h7jc-4w8p Severity: critical CVE: CVE-2026-73294
Semaphore U: OS Command Injection
# Summary An OS command injection in repository git_url handling lets any user holding the Manager or Owner role on any project (the normal project-collaborator roles) achieve remote code execution on the Semaphore server host. Using git's --upload-pack=<cmd> option, an attacker runs arbitrary commands.
Indicators of compromise
- CVE-2026-73294cve
- http://127.0.0.1:3000/url
- http://127.0.0.1:3000}url
Original source: https://github.com/advisories/GHSA-xp7j-h7jc-4w8p