Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cjbassi
Cjbassi gotop |
|
| Vendors & Products |
Cjbassi
Cjbassi gotop |
Fri, 02 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user. Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected. | |
| Title | Argument Injection leading to arbitrary process termination in gotop | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-10-02T17:42:17.586Z
Reserved: 2026-09-15T06:26:41.028Z
Link: CVE-2026-91784
No data.
Status : Deferred
Published: 2026-10-02T09:16:45.117
Modified: 2026-10-02T18:54:07.277
Link: CVE-2026-91784
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:45:41Z
-
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')