Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git's --upload-pack= option to inject and execute arbitrary shell commands when the server processes repository operations using the default cmd_git client.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-73682 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub
CVE-2026-73682
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.8
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 2%
- EPSS %ILE
- 73%
- KEV
- Not listed
Published
August 14, 2026
Last Modified
August 17, 2026
Advisory Details (4)
Auto-updated Aug 14, 2026Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling | Advisories | VulnCheck
https://www.vulncheck.com/advisories/semaphore-prior-to-version-os-command-injection-via-git-url-repository-handlingcommit 5d87656a6806 (semaphoreui/semaphore)
Fix landed in semaphoreui/semaphore commit 5d87656a6806 — awaiting tagged release
https://github.com/semaphoreui/semaphore/commit/5d87656a680600125fe78edec1f7a0d10484b52csemaphoreUI v2.18.13 OS Command Injection - Critical vulnerability · Advisory · semaphoreui/semaphore · GitHub
https://github.com/semaphoreui/semaphore/security/advisories/GHSA-xp7j-h7jc-4w8pGitHub - semaphoreui/semaphore: Modern UI and powerful API for Ansible, Terraform/OpenTofu/Terragrunt, PowerShell and other DevOps tools. · GitHub
https://github.com/semaphoreui/semaphoreVendor Advisories for CVE-2026-73682(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 28× in last 7d / 28× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-19 20:30 UTCEG score recompute▼ 8.80
- 2026-08-19 20:30 UTCGHSA enrichment
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 08:14 UTCGHSA enrichment
- 2026-08-18 19:59 UTCEG score recompute
- 2026-08-18 19:59 UTCGHSA enrichment
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 07:43 UTCGHSA enrichment
- 2026-08-17 19:27 UTCEG score recompute
- 2026-08-17 19:27 UTCGHSA enrichment
- 2026-08-17 18:55 UTCEG score recompute
- 2026-08-17 18:55 UTCGHSA enrichment
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 10:35 UTCGHSA enrichment
- 2026-08-16 22:20 UTCEG score recompute
- 2026-08-16 22:20 UTCGHSA enrichment
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 10:04 UTCEG score recompute
- 2026-08-16 10:04 UTCGHSA enrichment
- 2026-08-16 02:15 UTCEPSS rescore
- 2026-08-15 21:50 UTCGHSA enrichment
- 2026-08-15 09:35 UTCEG score recompute
- 2026-08-15 09:35 UTCGHSA enrichment
Show 3 moreShow fewer
- 2026-08-14 21:19 UTCEG score recompute
- 2026-08-14 21:14 UTCEG score recompute
- 2026-08-14 21:14 UTCMITRE cvelistV5first tracked
Frequently asked(5)
What is CVE-2026-73682?
When was CVE-2026-73682 disclosed?
Is CVE-2026-73682 actively exploited?
What is the CVSS score of CVE-2026-73682?
How do I remediate CVE-2026-73682?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-73682
Is Your Infrastructure Affected by CVE-2026-73682?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.