<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:33:34 +0000</lastBuildDate>
    <item>
      <title>BREW-glances-CVE-2026-68518 — Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68518</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68518</guid>
    </item>
    <item>
      <title>CVE-2026-68518 — Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-68518</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nicolargo glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nicolargo glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-68518</guid>
    </item>
    <item>
      <title>GHSA-qcpp-8x79-hhp3 — Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qcpp-8x79-hhp3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Glances action system lets an administrator configure shell commands that run
when a monitoring threshold is crossed. The command is a Mustache template whose
variables are filled with runtime stat fields such as a process name, a container
name or a filesystem mount point. Those fields are attacker-influenceable: a
local, unprivileged user who starts a process (or a container) controls its name
and command line. The rendered command is executed by `secure_popen()`, which
interprets `&amp;amp;&amp;amp;`, `|` and `&amp;gt;` as chaining / pipe / redirection operators.&lt;/p&gt;
&lt;p&gt;`glances/actions.py` defends against this with `_sanitize_mustache_dict()`, which
strips those operators from **each individual** template value before rendering.
The sanitization is applied per field, but the operators are reconstructed
**across the boundary of two adjacent template variables** after Mustache
rendering. When an action template concatenates two unescaped variables
(`{{{a}}}{{{b}}}` or `{{&amp;amp;a}}{{&amp;amp;b}}`) and the attacker makes the first value end
with `&amp;amp;` and the second begin with `&amp;amp;`, the rendered command contains a real
`&amp;amp;&amp;amp;`, and `secure_popen()` executes the injected command. The single-`&amp;amp;` in each
value passes the per-field filter untouched.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;`glances` `&amp;lt;= 4.5.5` (verified against the published PyPI release `4.5.5`, the
latest at the time of writing; `glances.__version__ == &amp;#34;4.5.5&amp;#34;`). The
per-field sanitizer `_sanitize_mustache_dict()` is present and active in this
release. Not…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Glances action system lets an administrator configure shell commands that run
when a monitoring threshold is crossed. The command is a Mustache template whose
variables are filled with runtime stat fields such as a process name, a container
name or a filesystem mount point. Those fields are attacker-influenceable: a
local, unprivileged user who starts a process (or a container) controls its name
and command line. The rendered command is executed by `secure_popen()`, which
interprets `&amp;amp;&amp;amp;`, `|` and `&amp;gt;` as chaining / pipe / redirection operators.&lt;/p&gt;
&lt;p&gt;`glances/actions.py` defends against this with `_sanitize_mustache_dict()`, which
strips those operators from **each individual** template value before rendering.
The sanitization is applied per field, but the operators are reconstructed
**across the boundary of two adjacent template variables** after Mustache
rendering. When an action template concatenates two unescaped variables
(`{{{a}}}{{{b}}}` or `{{&amp;amp;a}}{{&amp;amp;b}}`) and the attacker makes the first value end
with `&amp;amp;` and the second begin with `&amp;amp;`, the rendered command contains a real
`&amp;amp;&amp;amp;`, and `secure_popen()` executes the injected command. The single-`&amp;amp;` in each
value passes the per-field filter untouched.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;`glances` `&amp;lt;= 4.5.5` (verified against the published PyPI release `4.5.5`, the
latest at the time of writing; `glances.__version__ == &amp;#34;4.5.5&amp;#34;`). The
per-field sanitizer `_sanitize_mustache_dict()` is present and active in this
release. Not…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qcpp-8x79-hhp3</guid>
    </item>
  </channel>
</rss>
