<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:12:28.574976+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68518</id>
    <title>BREW-glances-CVE-2026-68518 — Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction</title>
    <updated>2026-10-04T15:12:28.611026+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-68518</id>
    <title>CVE-2026-68518 — Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction</title>
    <updated>2026-10-04T15:12:28.611102+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> nicolargo glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-68518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3668</id>
    <title>PYSEC-2026-3668 — Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction</title>
    <updated>2026-10-04T15:12:28.611169+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: glances</p>
<p>### Summary</p>
<p>The Glances action system lets an administrator configure shell commands that run
when a monitoring threshold is crossed. The command is a Mustache template whose
variables are filled with runtime stat fields such as a process name, a container
name or a filesystem mount point. Those fields are attacker-influenceable: a
local, unprivileged user who starts a process (or a container) controls its name
and command line. The rendered command is executed by `secure_popen()`, which
interprets `&amp;&amp;`, `|` and `&gt;` as chaining / pipe / redirection operators.</p>
<p>`glances/actions.py` defends against this with `_sanitize_mustache_dict()`, which
strips those operators from **each individual** template value before rendering.
The sanitization is applied per field, but the operators are reconstructed
**across the boundary of two adjacent template variables** after Mustache
rendering. When an action template concatenates two unescaped variables
(`{{{a}}}{{{b}}}` or `{{&amp;a}}{{&amp;b}}`) and the attacker makes the first value end
with `&amp;` and the second begin with `&amp;`, the rendered command contains a real
`&amp;&amp;`, and `secure_popen()` executes the injected command. The single-`&amp;` in each
value passes the per-field filter untouched.</p>
<p>### Affected versions</p>
<p>`glances` `&lt;= 4.5.5` (verified against the published PyPI release `4.5.5`, the
latest at the time of writing; `glances.__version__ == "4.5.5"`). The
per-field sanitizer `_sanitize_mustache_dict()` is present and active in this
release. Not…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3668"/>
  </entry>
</feed>
