Answer in brief
CVE-2026-108546 records a High severity (CVSS 7.7) vulnerability in Spotweb through 1.5.8 OS Command Injection via Spot Title in Runcommand Integration. The current sources do not mark it as known exploited. The current feed maps spotweb/spotweb (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps spotweb/spotweb (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| spotweb/spotwebgeneric | >=0 <=1.5.8 | Not reported |
Published upstream
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 10, 2026
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process.
Quoted source text, attributed separately from HOL analysis.