Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user. Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected. | |
| Title | Argument Injection leading to arbitrary process termination in gotop | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-10-02T08:42:17.946Z
Reserved: 2026-09-15T06:26:41.028Z
Link: CVE-2026-91784
No data.
Status : Received
Published: 2026-10-02T09:16:45.117
Modified: 2026-10-02T09:16:45.117
Link: CVE-2026-91784
No data.
OpenCVE Enrichment
Updated: 2026-10-02T10:30:07Z
-
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')