Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. Glances
  4. ›
  5. CVE-2026-32608

CVE-2026-32608: Glances has a Command Injection via Process Names in Action Command Templates

March 16, 2026 (updated March 19, 2026)

The Glances action system allows administrators to configure shell commands that execute when monitoring thresholds are exceeded. These commands support Mustache template variables (e.g., {{name}}, {{key}}) that are populated with runtime monitoring data. The secure_popen() function, which executes these commands, implements its own pipe, redirect, and chain operator handling by splitting the command string before passing each segment to subprocess.Popen(shell=False). When a Mustache-rendered value (such as a process name, filesystem mount point, or container name) contains pipe, redirect, or chain metacharacters, the rendered command is split in unintended ways, allowing an attacker who controls a process name or container name to inject arbitrary commands.

References

  • github.com/advisories/GHSA-vcv2-q258-wrg7
  • github.com/nicolargo/glances
  • github.com/nicolargo/glances/commit/6f4ec53d967478e69917078e6f73f448001bf107
  • github.com/nicolargo/glances/releases/tag/v4.5.2
  • github.com/nicolargo/glances/security/advisories/GHSA-vcv2-q258-wrg7
  • nvd.nist.gov/vuln/detail/CVE-2026-32608

Code Behaviors & Features

Detect and mitigate CVE-2026-32608 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.5.2

Fixed versions

  • 4.5.2

Solution

Upgrade to version 4.5.2 or above.

Impact 7 HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Source file

pypi/Glances/CVE-2026-32608.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:17:57 +0000.