Vulnerability in Glances Monitoring Tool Allows Dangerous Shell Command Execution
CVE-2026-68518
8.8HIGH
What is CVE-2026-68518?
The Glances monitoring tool, prior to version 4.5.6, contains a significant vulnerability in the _sanitize_mustache_dict() function. This flaw allows unescaped Mustache variables to be reconstructed, potentially leading to the execution of malicious shell commands through administrator-configured action templates. This issue has been addressed in version 4.5.6, which implements proper sanitization to prevent unauthorized command execution in rendered templates.
Affected Version(s)
glances < 4.5.6
