Puedes descargarlo en el proyecto github de GLPI Agent: https://github.com/glpi-project/glpi-agent/releases/tag/1.18
This new version is essentially a security fix release for the following security issues:
- [SECURITY - High] ToolBox plugin can allow unauthenticated path traversal (CVE-2026-40936)
- [SECURITY - High] MySQL and PostgreSQL database inventory command injection (CVE-2026-46615)
- [SECURITY - High] MongoDB database inventory Javascript injection (CVE-2026-45621)
- [SECURITY - High] Command injection via unsecured ToolBox plugin installation (CVE-2026-49285)
- [SECURITY - High] MSSQL database inventory command injection (CVE-2026-52764)
- [SECURITY - High] RCE in ToolBox Remotes page (CVE-2026-TODO)
- [SECURITY - Medium] File injection with Proxy plugin and rarely used configuration (CVE-2026-42187)
- [SECURITY - Medium] Oracle and DB2 database inventory SQL injection (CVE-2026-52765)
- [SECURITY - Medium] Deploy task Path Traversal in Tools::Archive (CVE-2026-52768)
- [SECURITY - Low] XSS on shared fields via unsecured ToolBox plugin installation
- [SECURITY - Low] XSS on credentials fields via unsecured ToolBox plugin installation
- [SECURITY - Low] Server-controlled regex compilation in Collect task
- [SECURITY - Low] Unvalidated process username use during Oracle database inventory
The release also includes few bug fixes:
- NVMe SSD storage disks support on MacOSX
- Lxd containers inventory update on Linux
- Network inventory update to support NetApp, Ubnt and Digi devices
- ToolBox plugin security has been enhanced
- DWService Remote_management inventory support
Puede consultar los detalles de los cambios en el registro de cambios oficial en línea disponible aquí: https://github.com/glpi-project/glpi-agent/blob/1.18/Changes
Respecto al embalaje, esto es lo que debes conservar:
- On Windows, GLPI Agent uses Perl 5.42.2, OpenSSL 3.5.7 and updated building toolchain
- The MacOSX packaging now uses Perl 5.42.2 and OpenSSL 3.5.7
- The Linux Snap packaging now uses Perl 5.42.2
- The Linux perl script installer was updated to fix upgrade against nightly build installation
This time, we strongly encourage you to update your agents.
