Cross-Platform Monitoring Tool Vulnerability in Glances by Nicolargo
CVE-2026-62982
8.8HIGH
What is CVE-2026-62982?
Glances, a popular open-source cross-platform monitoring tool, contains a vulnerability in its sanitization process. In versions ranging from 4.5.2 to 4.5.6, the function _sanitize_mustache_dict() fails to adequately handle nested list and dictionary strings, including critical process command-line values. This oversight allows potentially malicious pipe characters to escape the rendering process and be executed through administrator-defined action templates, risking the integrity of the system. The issue was rectified in the 4.5.6 update, emphasizing the necessity of using the latest version for secure operations.
Affected Version(s)
glances >= 4.5.2, < 4.5.6
