Impact
Glances omitted the "--disable-config-exec" flag when executing on‑alert action commands, allowing shell operators to be processed by secure_popen. This bypass enables arbitrary command execution or command chaining whenever an alert fires, exposing the system to full compromise. The weakness matches CWE‑78, an OS command injection flaw.
Affected Systems
The vulnerability affects the Glances monitoring tool from the nicolargo vendor. All releases prior to version 4.5.6 are affected; the issue is resolved in release 4.5.6 and later.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability represents a medium‑high risk. EPSS information is not available, and the flaw is not listed in CISA's KEV catalog. Attackers who can trigger or configure an alert can exploit this flaw to run arbitrary shell commands, making the threat significant for systems that rely on Glances for monitoring.
OpenCVE Enrichment
Github GHSA