Local Argument Injection Vulnerability in Gotop by Cjbassi
CVE-2026-91784

4.8MEDIUM

Key Information:

Vendor

Cjbassi

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-91784?

The Gotop application, developed by Cjbassi, contains a vulnerability that allows local argument injection through its process termination functionality. The issue arises when the application directly passes the process name to the 'pkill' command without any sanitization. This flaw enables an attacker to create a malicious process name starting with '--' that includes a target user's UID. If the user operating Gotop tries to terminate the crafted process, 'pkill' interprets the process name as a command-line option, leading to the termination of all processes associated with the targeted user. As of version 3.0.0, the product is no longer actively supported, and no fixes are available for this vulnerability.

Affected Version(s)

gotop 3.0.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)
.