CVE-2026-90770
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
13/09/2026
Last modified:
23/09/2026
Description
Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/openspug/spug
- https://github.com/openspug/spug/blob/v3.4.0/spug_api/apps/monitor/executors.py
- https://github.com/openspug/spug/blob/v3.4.0/spug_api/apps/monitor/views.py
- https://github.com/openspug/spug/commit/97aebf133e1f9cbb35ccebadab1faedfdfe93f42
- https://github.com/openspug/spug/issues/741
- https://www.vulncheck.com/advisories/spug-through-3.4.0-remote-code-execution-via-ping-check


