The open-source monitoring tool Glances released version 4.5.6 with multiple security fixes, including remediation for CVE-2026-68518, a high-severity command injection flaw in action-template handling. The vulnerability affected versions prior to 4.5.6 and stemmed from sanitizing individual Mustache values before chevron.render(), allowing attacker-controlled process or container fields placed in administrator-configured action templates to reconstruct shell operators across adjacent variables and reach secure_popen() as injected commands.
The release also closed an earlier incomplete fix tied to CVE-2026-32608 and GHSA-73wf-9vmv-5pv9, where top-level-only sanitization could be bypassed through nested values such as process cmdline lists. A June patch added recursive sanitization for strings inside lists, tuples, and dictionaries to neutralize operators like &&, |, >>, and > before rendering, and new tests were added for nested structures and process command-line data. Glances 4.5.6 further bundled fixes for CVE-2026-68520, CVE-2026-68519, CVE-2026-62982, and CVE-2026-68517, alongside non-security bug fixes.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-68518 states it was newly received by security-advisories@github.com, documenting a command injection flaw in Glances where adjacent Mustache variables could reconstruct shell operators before execution by secure_popen(). The record links the issue to GHSA-qcpp-8x79-hhp3 and notes it was fixed in Glances 4.5.6.
The CVE record for CVE-2026-62982 was received by security-advisories@github.com, documenting that Glances 4.5.2 through 4.5.5 had an incomplete fix for CVE-2026-32608 that allowed nested values such as process cmdline data to bypass sanitization and reach secure_popen() for command injection. The record notes the issue was fixed in Glances 4.5.6 and links it to GHSA-73wf-9vmv-5pv9.
Glances version 4.5.6 was released with fixes for CVE-2026-68520, CVE-2026-68519, CVE-2026-68518, CVE-2026-62982, and CVE-2026-68517, including the nested-value sanitizer bypass issue. The release notes state that versions prior to 4.5.6 were affected by these flaws and that the release also included numerous non-security bug fixes.
A Glances commit addressed an incomplete fix for CVE-2026-32608 after maintainers found the action-template sanitizer could be bypassed by nested values such as process cmdline data, leading to OS command injection. The patch added recursive sanitization for strings inside lists, tuples, and dictionaries and introduced tests covering nested and runtime rendering cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.