{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopenspugspug/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openspug:spug:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-108540"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Spug (\u003c= 3.4.0)","Spug (\u003c= 4.0.1)"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["OpenSpug"],"content_html":"\u003cp\u003eOpenSpug Spug versions up to 3.4.0 and 4.0.1 are vulnerable to remote OS command injection via the /exec/transfer endpoint in the File Transfer component. This vulnerability allows an unauthenticated or authenticated remote attacker to execute arbitrary system commands on the underlying server hosting the application. The vulnerability has been confirmed with a CVSS v3.1 base score of 9.9, and public exploit code is currently available. As of the disclosure, the vendor has not responded to vulnerability reports, leaving instances at high risk of compromise. Defenders should prioritize limiting network access to the Spug application and monitoring for unexpected child processes originating from the application service.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution on the application server. This allows attackers to gain unauthorized access to the system, exfiltrate sensitive configuration data, pivot into the internal network, or deploy further malicious payloads. Given the nature of the Spug platform, which is typically used for deployment and server management, a compromise could lead to the takeover of managed infrastructure across an entire organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict network access control lists (ACLs) to restrict access to the Spug management interface to trusted internal IP ranges.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at the /exec/transfer endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor process creation logs for the Spug application user (e.g., www-data or spug) spawning shells or unauthorized utility processes like /bin/sh, /bin/bash, or /usr/bin/python.\u003c/li\u003e\n\u003cli\u003eSince no patch is currently available from the vendor, consider isolating affected systems or disabling the File Transfer component if it is not strictly required.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T07:59:28Z","date_published":"2026-10-11T07:59:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-openspug-command-injection/","summary":"OpenSpug Spug versions 3.4.0, 4.0.1, and earlier contain a remote OS command injection vulnerability in the File Transfer component, which is currently subject to public exploit availability.","title":"CVE-2026-108540: Remote Command Injection in OpenSpug Spug","url":"https://feed.craftedsignal.io/briefs/2026-10-openspug-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:openspug:spug:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}