CVE-2026-62982High· 8.8▾ TwilightGlances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
0.1% → 0.2%
Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to survive chevron.render() and be executed by secure_popen() through administrator-configured action templates. This issue is fixed in 4.5.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
glances >= 4.5.2, < 4.5.6Patched in:
glances 4.5.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68519HighGlances is an open-source system cross-platform monitoring tool
CVE-2026-68518HighGlances is an open-source system cross-platform monitoring tool
CVE-2026-68517Medium· 6.5Glances is an open-source system cross-platform monitoring tool
CVE-2026-68520Medium· 5.3Glances is an open-source system cross-platform monitoring tool
CVE-2026-46606High· 7.8Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
CVE-2026-30930HighGlances has SQL Injection via Process Names in TimescaleDB Export