Vendor
Semaphore versions prior to 2.18.20 contain an argument injection vulnerability allowing authenticated users with Manager or Owner roles to achieve remote code execution via malicious git_url parameters.