Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git's --upload-pack= option to inject and execute arbitrary shell commands when the server processes repository operations using the default cmd_git client.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-73682 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub
CVE-2026-73682
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 8.8
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 1.6%
- EPSS %ILE
- 73rd
- KEV
- Not listed
Published
August 14, 2026
Last Modified
August 17, 2026
Advisory Details (4)
Auto-updated Aug 14, 2026Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling | Advisories | VulnCheck
https://www.vulncheck.com/advisories/semaphore-prior-to-version-os-command-injection-via-git-url-repository-handlingcommit 5d87656a6806 (semaphoreui/semaphore)
Fix landed in semaphoreui/semaphore commit 5d87656a6806 — awaiting tagged release
https://github.com/semaphoreui/semaphore/commit/5d87656a680600125fe78edec1f7a0d10484b52csemaphoreUI v2.18.13 OS Command Injection - Critical vulnerability · Advisory · semaphoreui/semaphore · GitHub
https://github.com/semaphoreui/semaphore/security/advisories/GHSA-xp7j-h7jc-4w8pGitHub - semaphoreui/semaphore: Modern UI and powerful API for Ansible, Terraform/OpenTofu/Terragrunt, PowerShell and other DevOps tools. · GitHub
https://github.com/semaphoreui/semaphoreVendor Advisories for CVE-2026-73682(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Affected Packages
(1 across 1 ecosystem)
Go(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| github.com/semaphoreui/semaphore | — |
| — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 3× in last 7d / 10× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-10-04 12:18 UTCGHSA enrichment
- 2026-10-01 05:54 UTCEG score recompute
- 2026-10-01 05:54 UTCGHSA enrichment
- 2026-09-27 23:28 UTCGHSA enrichment
- 2026-09-24 17:14 UTCGHSA enrichment
- 2026-09-21 09:19 UTCGHSA enrichment
- 2026-09-18 02:18 UTCGHSA enrichment
- 2026-09-14 20:40 UTCGHSA enrichment
- 2026-09-11 13:39 UTCGHSA enrichment
- 2026-09-08 07:56 UTCGHSA enrichment
- 2026-09-05 02:18 UTCGHSA enrichment
- 2026-09-01 20:40 UTCGHSA enrichment
- 2026-08-29 15:02 UTCGHSA enrichment
- 2026-08-26 07:45 UTCGHSA enrichment
- 2026-08-23 02:07 UTCGHSA enrichment
- 2026-08-19 20:30 UTCEG score recompute▼ 8.80
- 2026-08-19 20:30 UTCGHSA enrichment
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 08:14 UTCGHSA enrichment
- 2026-08-18 19:59 UTCEG score recompute
- 2026-08-18 19:59 UTCGHSA enrichment
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 07:43 UTCGHSA enrichment
- 2026-08-17 19:27 UTCEG score recompute
Show 18 moreShow fewer
- 2026-08-17 19:27 UTCGHSA enrichment
- 2026-08-17 18:55 UTCEG score recompute
- 2026-08-17 18:55 UTCGHSA enrichment
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 10:35 UTCGHSA enrichment
- 2026-08-16 22:20 UTCEG score recompute
- 2026-08-16 22:20 UTCGHSA enrichment
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 10:04 UTCEG score recompute
- 2026-08-16 10:04 UTCGHSA enrichment
- 2026-08-16 02:15 UTCEPSS rescore
- 2026-08-15 21:50 UTCGHSA enrichment
- 2026-08-15 09:35 UTCEG score recompute
- 2026-08-15 09:35 UTCGHSA enrichment
- 2026-08-14 21:19 UTCEG score recompute
- 2026-08-14 21:14 UTCEG score recompute
- 2026-08-14 21:14 UTCMITRE cvelistV5first tracked
Related CVEs(same product + same CWE)
Same product
3 shownGo:github.com/semaphoreui/semaphore
Frequently asked(5)
What is CVE-2026-73682?
When was CVE-2026-73682 disclosed?
Is CVE-2026-73682 actively exploited?
What is the CVSS score of CVE-2026-73682?
How do I remediate CVE-2026-73682?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-73682
Is Your Infrastructure Affected by CVE-2026-73682?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.