Skip to content
Threat Feed

Vendor

Glances

4 briefs RSS
high advisory

Incomplete Fix for Glances Configuration Command Execution Bypass

Glances versions up to 4.5.5 contain a vulnerability where the --disable-config-exec flag fails to sanitize shell operators in on-alert action commands, allowing arbitrary command execution or file redirection.

Glances +1 vulnerability remote-code-execution security-bypass command-injection local-privilege-escalation
2t 2c
high advisory

Glances Cross-Origin Information Disclosure via Unauthenticated REST API

Glances versions before 4.5.4 are vulnerable to cross-origin information disclosure, where a malicious website can retrieve sensitive system information from a running Glances instance due to a permissive CORS policy on the `/api/4/all` endpoint.

Glances information-disclosure cors webserver
2r 3t 1c
high advisory

Glances IP Plugin SSRF Vulnerability Leading to Credential Leakage

A server-side request forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api configuration parameter, allowing attackers to force outbound HTTP requests and potentially leak credentials via the Authorization header.

Glances ssrf credential-leakage python
3r 3t 1i
high advisory

Glances Command Injection Vulnerability via Dynamic Configuration

Glances versions 4.5.2 and earlier are vulnerable to command injection via dynamic configuration values, allowing arbitrary command execution with the privileges of the Glances process if an attacker can modify or influence configuration files, potentially leading to privilege escalation.

Glances command-injection privilege-escalation cve-2026-33641
2r 2t