CyberRota Analysis
AI-GeneratedSemaphore versions prior to 2.18.20 are vulnerable to an OS command injection flaw in the handling of the git_url parameter, allowing authenticated users with Manager or Owner roles to execute arbitrary shell commands on the server. This vulnerability poses a significant risk of remote code execution, potentially compromising the entire Semaphore server environment. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-73682
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
GitHub
Original NVD Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub