CVE-2026-91784
Received Received - Intake

Local Argument Injection in gotop

Vulnerability report for CVE-2026-91784, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CERT.PL

Description

cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user. Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cjbassi gotop to 3.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a local argument injection flaw in the gotop software (version 3.0.0). It occurs because the process name is passed directly to the pkill command without proper sanitization. An attacker can create a process with a crafted name starting with --, such as one containing a target user's UID. When the user running gotop tries to kill this process, pkill misinterprets the crafted name as a command-line option, leading to the termination of all processes owned by the targeted user.

Detection Guidance

Check for running gotop processes and inspect process names for crafted entries starting with --. Use commands like ps aux | grep gotop or pkill -l to review process names. If gotop is installed, verify its version matches 3.0.0 or similar.

Impact Analysis

This vulnerability allows a local attacker to terminate all processes owned by a specific user on the system. If the attacker targets your user account, they could disrupt your work by killing critical processes, leading to data loss or system instability. Since the software is no longer supported and unpatched, there is no fix available.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a local privilege escalation issue rather than a data breach or privacy violation. However, if the affected system processes or terminates processes handling sensitive data, improper termination could lead to unintended data exposure or service disruption, potentially violating operational integrity requirements in these standards.

Mitigation Strategies

Uninstall gotop immediately as it is no longer supported and unpatched. Remove any user accounts that may have executed gotop. Monitor system logs for unusual process terminations or crafted process names.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91784. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart