THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-73wf-9vmv-5pv9 (high) — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

[GHSA] GHSA-73wf-9vmv-5pv9 (high) — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

medgithub_advisoriesPublished 2026-08-17

GHSA-73wf-9vmv-5pv9 Severity: high CVE: CVE-2026-62982

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

## Summary CVE-2026-32608 ("Command Injection via Process Names in Action Command Templates") was fixed (commit `5680a5d`) by adding `_sanitize_mustache_dict`, which replaces the shell operators `&

Indicators of compromise

Original source: https://github.com/advisories/GHSA-73wf-9vmv-5pv9