Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53611— Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation

Quick assessment

Affected
AS203038 looking-glass
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Looking Glass 是一个现代的、无状态的网络诊断平台——它是一个自包含的单文件 Go 二进制程序,通过 SSH 连接管理一组路由器,并通过 gRPC(ConnectRPC)API、内嵌的 SvelteKit Web UI 以及 lg-cli 客户端提供 ping / traceroute / BGP 查询功能。在 1.3.5 版本之前,由于输入验证层中存在一个未锚定的正则表达式,导致存在操作系统命令注入漏洞。该问题已在 1.3.5 版本中修复。

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53611

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation
Source: CVE Program / CVE List V5
Vulnerability Description
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in the input validation layer. This issue has been patched in version 1.3.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
AS203038 looking-glass < 1.3.5 -

II. Public POCs for CVE-2026-53611

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53611

登录查看更多情报信息。

Other References for CVE-2026-53611 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53611

No comments yet


Leave a comment