VulnSea

semaphoreui has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 8.6 (high), with 1 rated critical. Most affected products: github.com/semaphoreui/semaphore (3), semaphore (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.6
Publish → KEV
Last 90 days
4 prev 0

Products

  • github.com/semaphoreui/semaphore 3
  • semaphore 1
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

semaphoreui vulnerabilities

CVEs affecting semaphoreui, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-91994Medium· 6.5PoC
1w ago

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credenti…

Twilightsemaphoreui · semaphoreEPSS 0.30%via NVD
CVE-2026-73294Critical· 9.9
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/projec…

Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.57%via NVD
CVE-2026-73292High· 8.3PoC
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-pa…

Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.23%via NVD
CVE-2026-73293High· 8.8
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to cre…

Twilightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.50%via NVD
semaphoreui vulnerabilities (CVEs) · VulnSea