Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
← Back to the register

github.com/semaphoreui/semaphore

CriticalGoCVE-2026-73294

What to do

Update github.com/semaphoreui/semaphore to 0.0.0-20260704181911-7e8a9434bd81 or later.

go get github.com/semaphoreui/semaphore@v0.0.0-20260704181911-7e8a9434bd81

A remote code execution flaw affects the Go package github.com/semaphoreui/semaphore. Affected versions: < 0.0.0-20260704181911-7e8a9434bd81. Fixed from version 0.0.0-20260704181911-7e8a9434bd81. CVSS score 9.9.

What the flaw allows: An attacker can make the service run their own code.

Package
github.com/semaphoreui/semaphore
Ecosystem
Go modules
Class
Remote code execution
Affected versions
< 0.0.0-20260704181911-7e8a9434bd81
CVSS
9.9
Published on
September 8, 2026

Sources

Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.