PatchSiren

semaphoreui CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL semaphoreui CVE published 2026-08-12

CVE-2026-73294

Semaphore UI, a web interface for managing DevOps tools, has a critical vulnerability prior to versions 2.18.17 and 2.19.5-beta2. The issue allows a project Manager or Owner to execute arbitrary OS commands in the Semaphore server process through repository git_url handling, specifically by passing an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash via POST /api/project/{i [truncated]

HIGH semaphoreui CVE published 2026-08-12

CVE-2026-73292

Semaphore UI, a web interface for managing DevOps tools, has a vulnerability prior to version 2.18.21. The /api/users/{id}/password endpoint is susceptible to cross-site request forgery (CSRF) attacks, allowing an unauthenticated attacker to change a user's password, including administrators, after user interaction. This issue is addressed in version 2.18.21.