CVE-2026-73682Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-15: 1Patch / Workaround · 2026-08-15: 1Technical Details · 2026-08-15: 108-15
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨HIGH - Semaphore RCE via git_url --upload-pack Argument Injection (CVE-2026-73682) Semaphore repository git_url handling allows argument injection into the default cmd_git client: a Manager/Owner can supply a crafted git_url with git --upload-pack= to execute shell commands during clone/fetch operations. Impact: remote code execution on the Semaphore server host. 👉Affected: semaphore < 2.18.20 | Upgrade to 2.18.20

    Post summary

    Semaphore repository git_url handling allows argument injection leading to remote code execution; upgrade to 2.18.20 to remediate.

    00000115
    289 followersView on X

Explore more