6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/semaphoreui/semaphore is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.8
CVE-2026-73293
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
HIGH 7.6
CVE-2026-73292
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
UNKNOWN
CVE-2026-73294
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
CRITICAL 9.9
CVE-2026-73294
Semaphore U: OS Command Injection
UNKNOWN
CVE-2026-73293
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore
UNKNOWN
CVE-2026-73292
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes