THREAT OPS › Threat News › [GHSA] GHSA-73wf-9vmv-5pv9 (high) — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
[GHSA] GHSA-73wf-9vmv-5pv9 (high) — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
GHSA-73wf-9vmv-5pv9 Severity: high CVE: CVE-2026-62982
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
## Summary CVE-2026-32608 ("Command Injection via Process Names in Action Command Templates") was fixed (commit `5680a5d`) by adding `_sanitize_mustache_dict`, which replaces the shell operators `&
Indicators of compromise
- CVE-2026-32608cve
- CVE-2026-62982cve
Original source: https://github.com/advisories/GHSA-73wf-9vmv-5pv9