Junglewise Threat Intelligence

CVE-2026-53611: Looking Glass OS command injection in BGP AS path validation

CVE-2026-53611 · Severity: critical · CVSS 9.8 · Published 2026-09-02

Executive brief

Looking Glass is a network diagnostic platform that exposes ping, traceroute, and BGP lookup capabilities through APIs and a web interface. An unauthenticated attacker can inject arbitrary shell commands via a malformed BGP AS path value, bypassing input validation and gaining complete control over the application container, including access to SSH credentials and infrastructure secrets.

Technical details

The vulnerability is an OS Command Injection (CWE-78) caused by an unanchored regular expression in the BGPASPath input validation layer. The regex performs a substring match rather than validating the entire input, allowing attackers to append shell metacharacters after valid numeric sequences (e.g., "65001';id;"). This bypass payload reaches an internal SSH execution template where it breaks out of single-quoted string context and executes arbitrary shell commands. The vulnerability is unauthenticated, network-reachable via the gRPC/HTTP2 API, requires no user interaction, and can lead to full container compromise and extraction of sensitive infrastructure credentials. Mitigation is available in version 1.3.5, which anchors the regex pattern to enforce strict whole-string validation.

Affected products

  • AS203038 Looking Glass before 1.3.5

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: patched: Version 1.3.5 released

References