Full Report
Local Argument Injection vulnerability (CVE-2026-91784) has been found in cjbassi/gotop software.
Analysis Summary
# Vulnerability: Local Argument Injection in cjbassi/gotop
## CVE Details
- **CVE ID:** CVE-2026-91784
- **CVSS Score:** Not explicitly listed in report (Severity: Medium/High due to Local Denial of Service potential)
- **CWE:** CWE-88 (Improper neutralization of argument delimiters in a command - 'argument injection')
## Affected Systems
- **Products:** cjbassi/gotop (Terminal-based graphical activity monitor)
- **Versions:** 3.0.0 (Other versions are likely affected but remain untested)
- **Configurations:** Systems where the `gotop` process termination (kill) functionality is used.
## Vulnerability Description
The `gotop` software contains a local argument injection flaw within its process termination feature. When a user attempts to "kill" a process through the `gotop` interface, the software passes the process name directly to the underlying `pkill` system command without proper sanitization.
Because process names beginning with dashes (e.g., `--`) are interpreted by `pkill` as command-line flags rather than positional arguments, an attacker can manipulate the behavior of the `pkill` command.
## Exploitation
- **Status:** PoC available (Technique described in report)
- **Complexity:** Low
- **Attack Vector:** Local
- **Technical Scenario:** A local attacker creates a process with a malicious name, such as `--u [TARGET_UID]`. If a user running `gotop` attempts to terminate this malicious process, the command executed becomes `pkill --u [TARGET_UID]`. Instead of killing the specific process, `pkill` interprets the flag and terminates every process belonging to the targeted UID.
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Local Denial of Service; can result in the termination of all user-owned processes)
## Remediation
### Patches
- **None:** The product is no longer actively supported by the vendor, and no official patches have been released.
### Workarounds
- **Disable/Avoid Kill Feature:** Users should avoid using the built-in "kill" shortcut within `gotop`.
- **Use Alternatives:** Switch to actively maintained forks or alternative system monitors (e.g., `htop`, `btop`) that handle process signals securely.
## Detection
- **Indicators of Compromise:** Unusual process names appearing in process lists (e.g., names starting with `--`).
- **Detection Methods:** Monitor system logs for unexpected mass process terminations by `pkill` initiated by the `gotop` parent process.
## References
- **Vendor Advisory:** None (Product EOL)
- **CERT Polska Advisory:** hxxps[://]cert[.]pl/en/advisories/CVE-2026-91784
- **CVE Record:** hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-91784
- **CWE-88 Details:** hxxps[://]cwe[.]mitre[.]org/data/definitions/88[.]html