VDB

CVE-2026-53925

CVE-2026-53925 PUBLISHED CVSS 7.8 HIGH

Reported by GitHub_M · Published June 25, 2026

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command. When Application Monitoring Process (AMP) modules load their command or service_cmd configuration values from glances.conf, those values are passed directly to secure_popen() with no sanitization. This allows an attacker who can modify the Glances configuration file to write arbitrary content to arbitrary filesystem paths (via >), chain arbitrary commands (via &&), or pipe command output to arbitrary programs (via |). This vulnerability is fixed in 4.5.5.

Risk Scores

CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
nicolargoglances>= 4.0.8, < 4.5.5
PyPIGlances4.0.8
nicolargoglances>= 4.0.8, < 4.5.5, >= 4.0.8, < 4.5.5

Timeline

  • Jun 23, 2026 CVE Published
  • Jun 26, 2026 Coalition ESS Score
  • Jun 26, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›