Impact
Spug failing to sanitize user-supplied monitor addresses causes the ping_check function to interpolate those strings directly into shell commands. An attacker who to the /monitor/run_test/ endpoint, inject shell metacharacters, and trigger arbitrary commands to execute in the context of the Spug process user. This grants the attacker remote code execution on the host, potentially enabling full system compromise. This vulnerability represents a CWE-78 OS Command Injection flaw.
Affected Systems
The vulnerability exists in the openspug:spug product through version 3.4.0. Any deployment that has not upgraded beyond v3.4.0 is susceptible.
Risk and Exploitability
The CVSS score of 8.7 makes this a high‑1% indicates a low but nonzero exploitation probability. The minimal prerequisites—only authentication with monitor permissions—suggest a significant likelihood of successful exploitation. The vulnerability is not listed in CISA KEV, but that status does not reduce the threat level; remote command execution remains possible. Successful exploitation would enable total compromise of the host system.
OpenCVE Enrichment