Vulnerability Report: GO-2026-6435
- CVE-2026-73294, GHSA-xp7j-h7jc-4w8p
- Affects: github.com/semaphoreui/semaphore
- Published: Sep 10, 2026
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
For detailed information about this vulnerability, visit https://github.com/semaphoreui/semaphore/security/advisories/GHSA-xp7j-h7jc-4w8p or https://nvd.nist.gov/vuln/detail/CVE-2026-73294.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/semaphoreui/semaphore/security/advisories/GHSA-xp7j-h7jc-4w8p
- https://nvd.nist.gov/vuln/detail/CVE-2026-73294
- https://github.com/semaphoreui/semaphore/commit/7e8a9434bd81b82cf42220151c74801ea97542d6
- https://github.com/semaphoreui/semaphore/commit/a7a7a33a64aea382a0726b3722856f298663eacf
- https://github.com/semaphoreui/semaphore/tree/v2.18.17
- https://github.com/semaphoreui/semaphore/tree/v2.19.5-beta2
- https://vuln.go.dev/ID/GO-2026-6435.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.