CPE
An authenticated user with Manager or Owner privileges can achieve remote code execution on the Semaphore server by injecting malicious arguments into the git_url field.