← Back to CVE List
CVE-2026-108546NVD
Vulnerability Summary
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process.
CVSS v4.0 Base Metrics — Score 7.7 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Attack RequirementsPresent
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- spotweb spotweb <= 1.5.8
- spotweb spotweb 1.5.8
External References
- https://hackmd.io/@haind/spotweb-runcommand-title-injection
- https://github.com/spotweb/spotweb
- https://github.com/spotweb/spotweb/blob/1.5.8/lib/services/NzbHandler/Services_NzbHandler_Runcommand.php#L41-L45
- https://www.vulncheck.com/advisories/spotweb-through-1.5.8-os-command-injection-via-spot-title-in-runcommand-integration