PatchSiren

OpenSpug CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenSpug CVE published 2026-10-11

CVE-2026-108540

A vulnerability was found in OpenSpug Spug up to 3.4.0/4.0.1 in the File Transfer component, which allows for OS command injection via the /exec/transfer file. The attack can be launched remotely. The exploit has been published, but the vendor did not respond to the disclosure. This vulnerability has significant implications for defenders, who should prioritize verifying the presence of this vulnerability [truncated]