THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qcpp-8x79-hhp3 (high) — Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

[GHSA] GHSA-qcpp-8x79-hhp3 (high) — Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

medgithub_advisoriesPublished 2026-08-17

GHSA-qcpp-8x79-hhp3 Severity: high CVE: CVE-2026-68518

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

### Summary

The Glances action system lets an administrator configure shell commands that run when a monitoring threshold is crossed. The command is a Mustache template whose variables are filled with runtime stat fields such as

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qcpp-8x79-hhp3