CVE-2026-108546

Source
https://cve.org/CVERecord?id=CVE-2026-108546
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108546.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-108546
Published
2026-10-10T14:15:52Z
Modified
2026-10-11T02:46:47Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Spotweb through 1.5.8 OS Command Injection via Spot Title in Runcommand Integration
Details

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108546.json"
}
References

Affected packages

Git / github.com/spotweb/spotweb

Affected ranges

Type
GIT
Repo
https://github.com/spotweb/spotweb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.5.8"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.2.1
1.4.1
1.4.5
1.4.8
1.4.9
1.5.0
1.5.1
1.5.3
1.5.4
1.5.5
1.5.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108546.json"