
A flaw in glances bypassed shell operator checks because its sanitizer only inspected top-level strings. Attacker-controlled lists (like cmdline) passed through raw into templates, enabling OS command injection (CVE-2026-62982). https://github.com/advisories/GHSA-73wf-9vmv-5pv9 https://t.co/zG7JFvIImm
Post summary
This tweet discloses a new OS command injection flaw in glances, detailing how sanitizer limitations allow raw input to be executed, and provides a GitHub advisory link for further information.
