
🚨HIGH - Semaphore RCE via git_url --upload-pack Argument Injection (CVE-2026-73682) Semaphore repository git_url handling allows argument injection into the default cmd_git client: a Manager/Owner can supply a crafted git_url with git --upload-pack= to execute shell commands during clone/fetch operations. Impact: remote code execution on the Semaphore server host. 👉Affected: semaphore < 2.18.20 | Upgrade to 2.18.20
Post summary
Semaphore repository git_url handling allows argument injection leading to remote code execution; upgrade to 2.18.20 to remediate.
