{"id":"CVE-2026-91784","title":"cjbassi/gotop is vulnerable to local argument injection via process termination functionality","summary":"cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with --…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-88"],"vendor":"cjbassi","product":"gotop","affected":["gotop 3.0.0"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T09:16:45.117","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91784","references":[{"url":"https://cert.pl/en/posts/2026/10/CVE-2026-91784","label":"cvd@cert.pl"},{"url":"https://github.com/cjbassi/gotop","label":"cvd@cert.pl"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-02T09:15:03.059Z","slug":"CVE-2026-91784","body":"## Overview\n\ncjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nProduct is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}