—
GO-2026-6435
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
Quick fix
GO-2026-6435 — github.com/semaphoreui/semaphore: upgrade to the fixed version with the command below.
go get github.com/semaphoreui/semaphore@v0.0.0-20260704181911-7e8a9434bd81Details
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/semaphoreui/semaphore
Introduced in:
0Fixed in: 0.0.0-20260704181911-7e8a9434bd81Fix
go get github.com/semaphoreui/semaphore@v0.0.0-20260704181911-7e8a9434bd81References
- https://github.com/semaphoreui/semaphore/security/advisories/GHSA-xp7j-h7jc-4w8p[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-73294[ADVISORY]
- https://github.com/semaphoreui/semaphore/commit/7e8a9434bd81b82cf42220151c74801ea97542d6[FIX]
- https://github.com/semaphoreui/semaphore/commit/a7a7a33a64aea382a0726b3722856f298663eacf[FIX]
- https://github.com/semaphoreui/semaphore/tree/v2.18.17[WEB]
- https://github.com/semaphoreui/semaphore/tree/v2.19.5-beta2[WEB]