CVE-2026-100369
Received Received - Intake

Command Injection in CliInvoke .NET Library

Vulnerability report for CVE-2026-100369, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1, as well as `AlastairLundy.CliInvoke` versions 2.0.0-alpha.1 through 2.0.0, contain an argument-injection vulnerability in `RunnerProcessFactory` on the 2.x line and `RunnerConfigurationFactory` on the 3.x line. These factories combine runner arguments, a caller-controlled target, and caller-controlled arguments into one `ProcessStartInfo.Arguments` string, allowing a double quote in the target or an argument to terminate an operating-system-level quoted region and inject unintended elements into the runner’s argument vector, potentially resulting in arbitrary command execution when a shell runner is used. The vulnerability is patched in `CliInvoke` versions 2.8.5, 2.9.4, 2.10.5, and 3.0.0-beta.2, and in `AlastairLundy.CliInvoke` version 2.0.2. No complete workaround is available; users unable to upgrade can partially mitigate the issue by removing double quotes from targets and arguments, additionally removing shell metacharacters when using shell runners, or bypassing the vulnerable factory and constructing a `ProcessConfiguration` with an explicit `ArgumentList`.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
alastairlundy cliinvoke From 2.0.0 (inc) to 2.8.4 (inc)
alastairlundy cliinvoke From 2.9.0 (inc) to 2.9.3 (inc)
alastairlundy cliinvoke From 2.10.0 (inc) to 2.10.4 (inc)
alastairlundy cliinvoke From 3.0.0-alpha.1 (inc) to 3.0.0-beta.1 (inc)
alastairlundy cliinvoke to 2.8.5 (exc)
alastairlundy cliinvoke to 2.9.4 (exc)
alastairlundy cliinvoke to 2.10.5 (exc)
alastairlundy cliinvoke to 3.0.0-beta.2 (exc)
alastairlundy cliinvoke to 2.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an argument-injection vulnerability in CliInvoke and AlastairLundy.CliInvoke .NET libraries. It affects versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1. The issue occurs in RunnerProcessFactory and RunnerConfigurationFactory where user-controlled inputs are combined into ProcessStartInfo.Arguments without proper sanitization. A double quote in input can break the argument string, allowing injection of unintended commands that may execute arbitrary code when using shell runners.

The vulnerability is fixed in patched versions: CliInvoke 2.8.5, 2.9.4, 2.10.5, 3.0.0-beta.2, and AlastairLundy.CliInvoke 2.0.2.

Detection Guidance

Detection involves checking for vulnerable versions of CliInvoke or AlastairLundy.CliInvoke in your .NET projects. Use commands like 'dotnet list package' to list installed packages and their versions. Look for versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, or 3.0.0-alpha.1 through 3.0.0-beta.1 for CliInvoke, or 2.0.0-alpha.1 through 2.0.0 for AlastairLundy.CliInvoke.

Impact Analysis

If you use vulnerable versions of CliInvoke or AlastairLundy.CliInvoke in your applications, an attacker could exploit this to execute arbitrary commands on your system. This could lead to data theft, system compromise, or further network infiltration depending on the privileges of the running process. The impact is high as it allows full control over command execution.

Compliance Impact

This vulnerability could lead to arbitrary command execution, which may result in unauthorized data access, modification, or exfiltration. For GDPR, this could violate principles of data protection and integrity, potentially leading to breaches requiring notification under Article 33. For HIPAA, it may compromise protected health information confidentiality or integrity, violating the Security Rule requirements for safeguarding electronic PHI.

Mitigation Strategies

Upgrade to patched versions: CliInvoke 2.8.5, 2.9.4, 2.10.5, or 3.0.0-beta.2, or AlastairLundy.CliInvoke 2.0.2. If upgrading is not possible, remove double quotes from targets and arguments, remove shell metacharacters when using shell runners, or bypass the vulnerable factory by constructing a ProcessConfiguration with an explicit ArgumentList.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100369. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart