GHSA-h5c4-vc34-6jcvHighCVSS 8.8

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that...

Published
September 13, 2026
Last Modified
September 13, 2026

🔗 CVE IDs covered (1)

📋 Description

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.

🔗 References (8)