Nicolas Hennion Glances是Nicolas Hennion个人开发者的一款系统监控工具。 Nicolas Hennion Glances 4.5.5之前版本存在安全漏洞,该漏洞源于CORS源列表实现中存在配置错误,当cors_origins包含多个条目时会静默回退到Access-Control-Allow-Origin: *,可能导致恶意网页从任意源向/RPC2发出CORS简单请求并读取完整的系统监控数据集。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-53925 | 7.8 HIGH | Glances: Arbitrary file write and command execution via `secure_popen` redirection and cha |
| CVE-2026-46607 | 7.8 HIGH | Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Executio |
| CVE-2026-46606 | 7.8 HIGH | Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/vir |
| CVE-2026-46611 | 5.3 MEDIUM | Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack |
No comments yet