CVE-2026-91784 PUBLISHED

Argument Injection leading to arbitrary process termination in gotop

Assigner: CERT-PL
Reserved: 15.09.2026 Published: 02.10.2026 Updated: 02.10.2026

cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user.

Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor cjbassi
Product gotop
Versions Default: unknown
  • Version 3.0.0 is affected

Credits

  • Michał Majchrowicz (AFINE Team) finder
  • Marcin Wyczechowski (AFINE Team) finder

References

Problem Types

  • CWE-88 Improper neutralization of argument delimiters in a command ('argument injection') CWE

Impacts

  • CAPEC-6 Argument Injection