CVE-2026-68518
Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.
| CWE | CWE-78 |
| Vendor | nicolargo |
| Product | glances |
| Published | Aug 17, 2026 |
| Last Updated | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for nicolargo glances
Be the first to know when new unknown vulnerabilities affecting nicolargo glances are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
nicolargo / glances
< 4.5.6