Local Argument Injection Vulnerability in Gotop by Cjbassi
CVE-2026-91784
What is CVE-2026-91784?
The Gotop application, developed by Cjbassi, contains a vulnerability that allows local argument injection through its process termination functionality. The issue arises when the application directly passes the process name to the 'pkill' command without any sanitization. This flaw enables an attacker to create a malicious process name starting with '--' that includes a target user's UID. If the user operating Gotop tries to terminate the crafted process, 'pkill' interprets the process name as a command-line option, leading to the termination of all processes associated with the targeted user. As of version 3.0.0, the product is no longer actively supported, and no fixes are available for this vulnerability.
Affected Version(s)
gotop 3.0.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
