{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/semaphore/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-73682"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Semaphore (\u003c 2.18.20)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Semaphore"],"content_html":"\u003cp\u003eSemaphore versions prior to 2.18.20 are affected by an OS command injection vulnerability, specifically categorized as argument injection. The flaw exists in the handling of repository 'git_url' configurations. Authenticated users assigned the 'Manager' or 'Owner' role on any project can exploit this by crafting a malicious 'git_url' string containing the '--upload-pack=' git option.\u003c/p\u003e\n\u003cp\u003eWhen the application processes repository operations using the internal 'cmd_git' client, the crafted input allows the injection of arbitrary shell commands. Because the 'cmd_git' client executes these commands with the privileges of the Semaphore server application, successful exploitation results in remote code execution on the underlying server host. Given the elevated roles required (Manager/Owner), this vulnerability represents a significant risk for lateral movement or persistence within the CI/CD pipeline infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a critical risk to the integrity and availability of Semaphore instances. Successful exploitation allows unauthorized execution of system commands, potentially leading to full system compromise, exfiltration of sensitive source code, or modification of deployment pipelines. Organizations using Semaphore versions below 2.18.20 are impacted, particularly those with internal project environments where account security might be lower or trust models rely on the internal authorization framework.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Semaphore to version 2.18.20 or later immediately to patch CVE-2026-73682.\u003c/li\u003e\n\u003cli\u003eAudit project roles to identify and restrict 'Manager' or 'Owner' permissions to only necessary personnel to minimize the potential attack surface.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the Semaphore server to prevent the execution of outbound payloads or connection to attacker-controlled C2 infrastructure in the event of successful command injection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T22:14:39Z","date_published":"2026-08-14T22:14:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-semaphore-rce/","summary":"Semaphore versions prior to 2.18.20 contain an argument injection vulnerability allowing authenticated users with Manager or Owner roles to achieve remote code execution via malicious git_url parameters.","title":"CVE-2026-73682 Remote Code Execution in Semaphore","url":"https://feed.craftedsignal.io/briefs/2026-08-semaphore-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Semaphore","version":"https://jsonfeed.org/version/1.1"}