CVE-2026-73292: Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
The password change form is vulnerable to CSRF, allowing an attacker to change a user password (even the administrator) by tricking a connected user to visit a malicious website. The vulnerability has been tested with version 2.18.20.
References
- github.com/advisories/GHSA-8cj9-r88m-8945
- github.com/semaphoreui/semaphore/commit/2d6e2e3eb10e8bf688e2ab59609b909a012fad4c
- github.com/semaphoreui/semaphore/commit/c59c3dc9035badcbf0609c7d35679c06e590a956
- github.com/semaphoreui/semaphore/releases/tag/v2.18.21
- github.com/semaphoreui/semaphore/security/advisories/GHSA-8cj9-r88m-8945
- nvd.nist.gov/vuln/detail/CVE-2026-73292
Code Behaviors & Features
Detect and mitigate CVE-2026-73292 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →