<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:37:03 +0000</lastBuildDate>
    <item>
      <title>BREW-glances-CVE-2026-62982 — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdlin…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-62982</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to survive chevron.render() and be executed by secure_popen() through administrator-configured action templates. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to survive chevron.render() and be executed by secure_popen() through administrator-configured action templates. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-62982</guid>
    </item>
    <item>
      <title>CVE-2026-62982 — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdlin…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-62982</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nicolargo glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to survive chevron.render() and be executed by secure_popen() through administrator-configured action templates. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nicolargo glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to survive chevron.render() and be executed by secure_popen() through administrator-configured action templates. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-62982</guid>
    </item>
    <item>
      <title>GHSA-73wf-9vmv-5pv9 — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdlin…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-73wf-9vmv-5pv9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;## Summary
CVE-2026-32608 (&amp;#34;Command Injection via Process Names in Action Command Templates&amp;#34;) was fixed (commit `5680a5d`) by adding `_sanitize_mustache_dict`, which replaces the shell operators `&amp;amp;&amp;amp;`, `|`, `&amp;gt;&amp;gt;`, `&amp;gt;` with spaces in the values rendered into action command templates.&lt;/p&gt;
&lt;p&gt;The sanitizer only processes **top-level string** values (`if isinstance(v, str)`). Attacker-controlled **nested** values — most notably a process&amp;#39;s **`cmdline`, which Glances exposes as a `list`** and which is fully attacker-controlled via argv — are passed through **unsanitized**. Because the Mustache renderer (`chevron`) does **not** HTML-escape the pipe character `|`, a `|` embedded in such a nested value survives into the rendered command and is then interpreted by `secure_popen` (which still interprets `&amp;amp;&amp;amp;`/`|`/`&amp;gt;` by default, `allow_operators=True`), re-introducing the exact command injection the CVE was meant to close.&lt;/p&gt;
&lt;p&gt;## Details
The fix (`glances/actions.py`):
```python
_SHELL_OPERATORS = (&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;|&amp;#39;, &amp;#39;&amp;gt;&amp;gt;&amp;#39;, &amp;#39;&amp;gt;&amp;#39;)                     # line 25&lt;/p&gt;
&lt;p&gt;def _sanitize_mustache_dict(mustache_dict):                   # line 28
    ...
    for k, v in mustache_dict.items():
        if isinstance(v, str):                                # line 40  &amp;lt;-- ONLY top-level strings
            for op in _SHELL_OPERATORS:
                v = v.replace(op, &amp;#39; &amp;#39;)
            safe[k] = v
        else:
            safe[k] = v                                       # nested list/dict passed VERBATIM
    return safe
```
R…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;## Summary
CVE-2026-32608 (&amp;#34;Command Injection via Process Names in Action Command Templates&amp;#34;) was fixed (commit `5680a5d`) by adding `_sanitize_mustache_dict`, which replaces the shell operators `&amp;amp;&amp;amp;`, `|`, `&amp;gt;&amp;gt;`, `&amp;gt;` with spaces in the values rendered into action command templates.&lt;/p&gt;
&lt;p&gt;The sanitizer only processes **top-level string** values (`if isinstance(v, str)`). Attacker-controlled **nested** values — most notably a process&amp;#39;s **`cmdline`, which Glances exposes as a `list`** and which is fully attacker-controlled via argv — are passed through **unsanitized**. Because the Mustache renderer (`chevron`) does **not** HTML-escape the pipe character `|`, a `|` embedded in such a nested value survives into the rendered command and is then interpreted by `secure_popen` (which still interprets `&amp;amp;&amp;amp;`/`|`/`&amp;gt;` by default, `allow_operators=True`), re-introducing the exact command injection the CVE was meant to close.&lt;/p&gt;
&lt;p&gt;## Details
The fix (`glances/actions.py`):
```python
_SHELL_OPERATORS = (&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;|&amp;#39;, &amp;#39;&amp;gt;&amp;gt;&amp;#39;, &amp;#39;&amp;gt;&amp;#39;)                     # line 25&lt;/p&gt;
&lt;p&gt;def _sanitize_mustache_dict(mustache_dict):                   # line 28
    ...
    for k, v in mustache_dict.items():
        if isinstance(v, str):                                # line 40  &amp;lt;-- ONLY top-level strings
            for op in _SHELL_OPERATORS:
                v = v.replace(op, &amp;#39; &amp;#39;)
            safe[k] = v
        else:
            safe[k] = v                                       # nested list/dict passed VERBATIM
    return safe
```
R…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-73wf-9vmv-5pv9</guid>
    </item>
  </channel>
</rss>
