Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-91784— Argument Injection leading to arbitrary process termination in gotop

Quick assessment

Affected
cjbassi gotop
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

cjbassi/gotop 存在本地参数注入漏洞,该漏洞利用其进程终止功能导致。进程名称未经过任何处理或过滤,直接传递给 命令。本地攻击者可以创建一个名称以 开头(例如包含目标用户的 UID)的恶意进程。当运行 gotop 的用户对该进程使用“终止”功能时, 会将该恶意指定的进程名解析为命令行选项,从而导致目标用户拥有的所有进程被终止。 该产品已不再得到积极维护,且该漏洞尚未修复。此漏洞已在版本 3.0.0 中得到确认;其他版本未经过测试,但也可能受到相同影响。

CVSS 4.8 · Medium EPSS 0.15% · P4

Possible ATT&CK Techniques 1 AI

T1055.001 · Dynamic-link Library Injection

Affected Version Matrix 1

VendorProduct Version RangeStatus
cjbassi gotop 3.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91784

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Argument Injection leading to arbitrary process termination in gotop
Source: CVE Program / CVE List V5
Vulnerability Description
cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user. Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
参数注入或修改
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cjbassi gotop 3.0.0 -

II. Public POCs for CVE-2026-91784

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91784

请登录查看更多情报信息。

Security Blog Posts for CVE-2026-91784 (1)

Other References for CVE-2026-91784 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-91784

No comments yet


Leave a comment