THREAT OPS › Threat News › [GHSA] GHSA-qcpp-8x79-hhp3 (high) — Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
[GHSA] GHSA-qcpp-8x79-hhp3 (high) — Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
GHSA-qcpp-8x79-hhp3 Severity: high CVE: CVE-2026-68518
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
### Summary
The Glances action system lets an administrator configure shell commands that run when a monitoring threshold is crossed. The command is a Mustache template whose variables are filled with runtime stat fields such as
Indicators of compromise
- CVE-2026-68518cve
- CVE-2026-32608cve
Original source: https://github.com/advisories/GHSA-qcpp-8x79-hhp3