CVE-2026-53925

Source
https://cve.org/CVERecord?id=CVE-2026-53925
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53925.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53925
Aliases
Downstream
Related
Published
2026-06-25T18:03:43Z
Modified
2026-08-12T03:51:17Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Glances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
Details

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command. When Application Monitoring Process (AMP) modules load their command or service_cmd configuration values from glances.conf, those values are passed directly to secure_popen() with no sanitization. This allows an attacker who can modify the Glances configuration file to write arbitrary content to arbitrary filesystem paths (via >), chain arbitrary commands (via &&), or pipe command output to arbitrary programs (via |). This vulnerability is fixed in 4.5.5.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53925.json"
}
References

Affected packages

Git / github.com/nicolargo/glances

Affected ranges

Type
GIT
Repo
https://github.com/nicolargo/glances
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.0.8"
        },
        {
            "fixed": "4.5.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53925.json"