{"id":"CVE-2026-91784","summary":"Argument Injection leading to arbitrary process termination in gotop","details":"cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nProduct is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.","modified":"2026-10-04T02:47:12.804458576Z","published":"2026-10-02T08:38:42.744Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91784.json","cna_assigner":"CERT-PL","cwe_ids":["CWE-88"]},"references":[{"type":"ADVISORY","url":"https://cert.pl/en/posts/2026/10/CVE-2026-91784"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91784.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91784"},{"type":"PACKAGE","url":"https://github.com/cjbassi/gotop"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cjbassi/gotop","events":[{"introduced":"867cf2b9e4a4acfd8bbfbe5c8d67aa2450d669e2"},{"last_affected":"867cf2b9e4a4acfd8bbfbe5c8d67aa2450d669e2"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"last_affected":"3.0.0"}],"source":"AFFECTED_FIELD"}}],"versions":["3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91784.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}