CVE-2026-68518High▾ TwilightGlances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
0.1% → 0.2%
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
glances <= 4.5.5Patched in:
glances 4.5.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62982High· 8.8Glances is an open-source system cross-platform monitoring tool
CVE-2026-68519HighGlances is an open-source system cross-platform monitoring tool
CVE-2026-68517Medium· 6.5Glances is an open-source system cross-platform monitoring tool
CVE-2026-68520Medium· 5.3Glances is an open-source system cross-platform monitoring tool
CVE-2026-46606High· 7.8Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
CVE-2026-30930HighGlances has SQL Injection via Process Names in TimescaleDB Export