---
id: CVE-2026-108546
title: >-
  Spotweb through 1.5.8 contains an OS command injection vulnerability in the
  runcommand NZB handler that allows remote attackers to execute commands by
  publishing spots with malicious titles
summary: >-
  Spotweb through 1.5.8 contains an OS command injection vulnerability in the
  runcommand NZB handler that allows remote attackers to execute commands by
  publishing spots with malicious titles. Attackers can post self-signed spots
  over Usen…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T15:16:57.573'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108546'
references:
  - url: 'https://github.com/spotweb/spotweb'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/spotweb/spotweb/blob/1.5.8/lib/services/NzbHandler/Services_NzbHandler_Runcommand.php#L41-L45
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@haind/spotweb-runcommand-title-injection'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/spotweb-through-1.5.8-os-command-injection-via-spot-title-in-runcommand-integration
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T15:25:58.086Z'
---

## Overview

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
