spug vulnerability

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.

Published 13 Sep 2026Updated 13 Sep 20266 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.