CVE-2026-53925
Reported by GitHub_M · Published June 25, 2026
Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command. When Application Monitoring Process (AMP) modules load their command or service_cmd configuration values from glances.conf, those values are passed directly to secure_popen() with no sanitization. This allows an attacker who can modify the Glances configuration file to write arbitrary content to arbitrary filesystem paths (via >), chain arbitrary commands (via &&), or pipe command output to arbitrary programs (via |). This vulnerability is fixed in 4.5.5.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nicolargo | glances | >= 4.0.8, < 4.5.5 |
| PyPI | Glances | 4.0.8 |
| nicolargo | glances | >= 4.0.8, < 4.5.5, >= 4.0.8, < 4.5.5 |
Timeline
- Jun 23, 2026 CVE Published
- Jun 26, 2026 Coalition ESS Score
- Jun 26, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
References
- https://github.com/nicolargo/glances/security/advisories/GHSA-3vwc-qwhc-3mj7 x_refsource_CONFIRM
- https://github.com/nicolargo/glances/releases/tag/v4.5.5 fix
- https://nvd.nist.gov/vuln/detail/CVE-2026-53925 advisory
- https://github.com/advisories/GHSA-3vwc-qwhc-3mj7 advisory
- https://github.com/nicolargo/glances url
- https://github.com/pypa/advisory-database/tree/main/vulns/glances/PYSEC-2026-2494.yaml advisory
- https://pypi.org/project/glances url