A vulnerability, which was classified as problematic, was found in Semaphoreui Semaphore up to 2.18.16/2.19.5-beta1. This impacts the function
GetLastRemoteCommitHash of the component Git Repository Handler. Such manipulation of the argument upload-pack leads to os command injection.
This vulnerability is referenced as CVE-2026-73294. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.