CVE-2026-53925

Source
https://cve.org/CVERecord?id=CVE-2026-53925
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53925.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-53925
Aliases
Downstream
Published
2026-06-25T18:03:43.333Z
Modified
2026-06-26T04:11:04.922190868Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Glances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
Details

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the securepopen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command. When Application Monitoring Process (AMP) modules load their command or servicecmd configuration values from glances.conf, those values are passed directly to secure_popen() with no sanitization. This allows an attacker who can modify the Glances configuration file to write arbitrary content to arbitrary filesystem paths (via >), chain arbitrary commands (via &&), or pipe command output to arbitrary programs (via |). This vulnerability is fixed in 4.5.5.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53925.json",
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nicolargo/glances

Affected ranges

Type
GIT
Repo
https://github.com/nicolargo/glances
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "4.0.8"
        },
        {
            "fixed": "4.5.5"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53925.json"