Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77)
A command injection vulnerability exists in the file transfer functionality (/exec/transfer) of OpenSpug Spug up to versions 3.4.0 and 4.0.1, allowing manipulation of input to execute arbitrary OS commands.
An authenticated user with low privileges can remotely execute arbitrary operating system commands on the affected server, including reading sensitive files, modifying system configuration, installing malware, or disrupting service availability.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Yes, a patch is available. A security advisory has been published at as of October 11, 2026.
Update OpenSpug Spug to a patched version beyond 4.0.1. If an immediate patch is unavailable, restrict network access to the /exec/transfer endpoint and implement strict input validation on the file transfer functionality. Consider implementing Web Application Firewall (WAF) rules to detect and block command injection patterns. Audit logs for suspicious file transfer activities and unauthorized command execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-108540 . See article
NVD published the first details for CVE-2026-108540
A CVSS base score of 9.9 has been assigned.
A critical OS command injection vulnerability with a CVSS score of 9.9 has been identified in OpenSpug versions up to 3.4.0/4.0.1, allowing remote attackers to execute arbitrary OS commands without explicit authentication. While no public proof-of-concept exploits are available, there is currently an advisory in review for mitigation, and no patches have been released. Exploitation of this flaw could lead to full system compromise, but its impact on downstream third-party vendors remains unspecified. See article
GitHub Advisories released a security advisory .
OpenSpug Spug CVE-2026-108540 - CVSS 9.9 RCE
CVE-2026-108540: OpenSpug Spug Critical OS Command Injection in File Transfer Component
CVE-2026-108860: BotSharp Authentication Bypass via Hard-coded JWT Secret Enables Admin Impersonation
CVE Daily Brief — 2026-10-11
CVE-2026-108860: BotSharp Authentication Bypass via Hard-coded JWT Secret Enables Admin Impersonation
CVE-2026-108753: Agnaistic Agnai Hard-Coded Credentials Enable Unauthenticated Admin Takeover
CVE-2026-66568: Original PHP Object Injection Permits Unauthenticated Remote Code Execution
Be the first to know critical vulnerabilities
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
