Description
A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-11
Score: 9.4 Critical
EPSS: 1.7% Low
KEV: No
Impact: Remote code execution via OS command injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection in the file transfer component of OpenSpug. An attacker can manipulate an unknown function in the /exec/transfer endpoint to execute arbitrary shell commands on the host, leading to full compromise of the system. This flaw corresponds to generic OS command injection weaknesses (CWE-77, CWE-78).

Affected Systems

The issue affects OpenSpug releases up to and including 3.4.0 and 4.0.1, as distributed by OpenSpug:Spug.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. The EPSS score is not available, but the exploit is publicly published and may be in use. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, exploiting the /exec/transfer request over the network. Because the flaw permits unrestricted command execution, any remote attacker who can reach the endpoint can gain full control of the host, making the risk extremely high.

Generated by OpenCVE AI on October 11, 2026 at 07:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenSpug to a version that fixes the command‑injection flaw (e.g., 3.4.1 or later, 4.0.2 or later).
  • If an upgrade is not immediately possible, restrict access to the /exec/transfer endpoint using firewall rules or network ACLs so that only trusted internal IPs can reach it.
  • If the endpoint must remain exposed, apply input validation or sanitization to the parameters of /exec/transfer, ensuring only allowed commands or arguments can be executed.

Generated by OpenCVE AI on October 11, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title OpenSpug File Transfer transfer os command injection
First Time appeared Openspug
Openspug spug
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:openspug:spug:*:*:*:*:*:*:*:*
Vendors & Products Openspug
Openspug spug
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T06:00:16.538Z

Reserved: 2026-10-10T13:23:54.823Z

Link: CVE-2026-108540

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T07:17:23.303

Modified: 2026-10-11T07:17:23.643

Link: CVE-2026-108540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:30:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')