---
id: CVE-2026-100368
title: >-
  CliInvoke is a .NET library for invoking command-line programs, and its
  `CliInvoke.Specializations` packages provide specialized wrappers for shells
  such as PowerShell and Windows Command Prompt
summary: >-
  CliInvoke is a .NET library for invoking command-line programs, and its
  `CliInvoke.Specializations` packages provide specialized wrappers for shells
  such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations`
  versions 2.2.…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: alastairlundy
product: CliInvoke.Specializations
affected:
  - 'CliInvoke.Specializations >= 2.2.0, <= 2.8.4'
  - 'CliInvoke.Specializations >= 2.9.0, <= 2.9.3'
  - 'CliInvoke.Specializations >= 2.10.0, <= 2.10.4'
  - 'CliInvoke.Specializations >= 3.0.0-alpha.1, <= 3.0.0-alpha.4'
  - 'CliInvoke.Specializations >= 3.0.0-alpha.8, <= 3.0.0-alpha.10'
  - 'CliInvoke.Specializations >= 1.0.0-rc.1, <= 1.6.1.1'
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T20:17:05.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100368'
references:
  - url: >-
      https://github.com/alastairlundy/CliInvoke/security/advisories/GHSA-wrvw-254r-wpmv
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100368'
  - url: >-
      https://github.com/alastairlundy/CliInvoke/commit/1e98582f02eb43e345e5b97b8dd6ff9443806685
  - url: >-
      https://github.com/alastairlundy/CliInvoke/commit/2077e5239850e83dc9cc67ae6036dcd4e68a1876
  - url: 'https://github.com/alastairlundy/CliInvoke/releases/tag/2.10.5'
  - url: 'https://github.com/alastairlundy/CliInvoke/releases/tag/3.0.0-beta.1'
  - url: 'https://github.com/advisories/GHSA-wrvw-254r-wpmv'
tags:
  - nvd
  - cve.org
  - ghsa
  - nuget
ingestedAt: '2026-09-25T20:17:49.418Z'
aliases:
  - GHSA-wrvw-254r-wpmv
ecosystem: nuget
patched:
  - CliInvoke.Specializations 2.8.5
  - CliInvoke.Specializations 2.9.4
  - CliInvoke.Specializations 2.10.5
  - CliInvoke.Specializations 3.0.0-beta.1
  - CliInvoke.Specializations 3.0.0-beta.1
  - AlastairLundy.CliInvoke.Specializations 2.0.2
epss: 0.00581
epssPercentile: 0.45541
---

## Overview

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, 3.0.0-alpha.1 through 3.0.0-alpha.4, and 3.0.0-alpha.8 through 3.0.0-alpha.10, as well as `AlastairLundy.CliInvoke.Specializations` versions 1.0.0-rc.1 through 1.6.1.1, contain an OS command injection vulnerability in their PowerShell and Cmd wrappers. The wrappers pass a caller-controlled target and arguments to `pwsh -Command` or `cmd /c` using a single `ProcessStartInfo.Arguments` string, allowing a double quote in untrusted input to break operating-system-level quoting and cause the shell to execute an additional command with the host process's privileges. The vulnerability is patched in `CliInvoke.Specializations` versions 2.8.5, 2.9.4, 2.10.5, and 3.0.0-beta.1, and in `AlastairLundy.CliInvoke.Specializations` version 2.0.2. No complete workaround is available; users unable to upgrade should reject or remove double quotes from target paths and arguments, additionally reject shell metacharacters in versions 2.2.0 through 2.9.2 and 3.0.0-alpha.1 through 3.0.0-alpha.4, or bypass the PowerShell and Cmd wrappers and invoke target processes directly when handling untrusted input.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-100368)

Affected packages:

- `CliInvoke.Specializations >= 2.2.0, <= 2.8.4`
- `CliInvoke.Specializations >= 2.9.0, <= 2.9.3`
- `CliInvoke.Specializations >= 2.10.0, <= 2.10.4`
- `CliInvoke.Specializations >= 3.0.0-alpha.1, <= 3.0.0-alpha.4`
- `CliInvoke.Specializations >= 3.0.0-alpha.8, <= 3.0.0-alpha.10`
- `AlastairLundy.CliInvoke.Specializations >= 1.0.0-rc.1, <= 1.6.1.1`

Patched in:

- `CliInvoke.Specializations 2.8.5`
- `CliInvoke.Specializations 2.9.4`
- `CliInvoke.Specializations 2.10.5`
- `CliInvoke.Specializations 3.0.0-beta.1`
- `CliInvoke.Specializations 3.0.0-beta.1`
- `AlastairLundy.CliInvoke.Specializations 2.0.2`

Source: https://github.com/advisories/GHSA-wrvw-254r-wpmv
