| CVE ID | CVE-2026-91784 |
| Publication date | 02 October 2026 |
| Vendor | cjbassi |
| Product | gotop |
| Vulnerable versions | 3.0.0 |
| Vulnerability type (CWE) | Improper neutralization of argument delimiters in a command ('argument injection') (CWE-88) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in cjbassi/gotop software and participated in coordination of its disclosure.
The vulnerability CVE-2026-91784: cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user.
Product is no longer actively supported and the vulnerability has not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.
Credits
We thank Michał Majchrowicz and Marcin Wyczechowski from AFINE Team for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.