---
id: CVE-2026-91784
title: >-
  cjbassi/gotop is vulnerable to local argument injection via process
  termination functionality
summary: "cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill\_without sanitization. A local attacker can create a process with a crafted name beginning with --…"
severity: medium
cvss: 4.8
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-88
vendor: cjbassi
product: gotop
affected:
  - gotop 3.0.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T09:16:45.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91784'
references:
  - url: 'https://cert.pl/en/posts/2026/10/CVE-2026-91784'
    label: cvd@cert.pl
  - url: 'https://github.com/cjbassi/gotop'
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T09:15:03.059Z'
---

## Overview

cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user.




















Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
