← Back to overview

CVE-2026-53611 affects Looking Glass, a stateless network-diagnostic platform built as a single Go binary that interfaces with routers via SSH and exposes ping, traceroute, and BGP lookup functionality. The vulnerability is an OS Command Injection flaw caused by an unanchored regular expression in the input validation layer, which allows attackers to inject arbitrary OS commands. The affected platform exposes a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client, making the attack surface broad. All versions prior to 1.3.5 are vulnerable. The issue has been fully patched in version 1.3.5. Users are strongly advised to upgrade immediately. The vulnerability was publicly disclosed via GitHub security advisories and the NVD. No workaround short of upgrading is described in the advisory.

Affected products

  • Looking Glass (AS203038)

Related CVE's

  • CVE-2026-53611

Categories

  • Network Infrastructure
  • Web Technologies