rootpwn

critical · CVSS v3 9.8 · CVSS v4 4.8 · EPSS 0.00154

CVE-2026-91784

cjbassi/gotop 3.0.0 is vulnerable to local argument injection via its process termination feature. An attacker can craft a process name begi

Overview

cjbassi/gotop 3.0.0 is vulnerable to local argument injection via its process termination feature. An attacker can craft a process name beginning with "--" to cause pkill to interpret it as an option, leading to unintended termination of all processes owned by a target user. This flaw can allow local privilege escalation and denial of service.

Description

cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user. Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.

Impact

The vulnerability compromises confidentiality by allowing an attacker to terminate processes of other users, integrity by disrupting legitimate workloads, and availability by causing denial of service. It affects any system where gotop is installed and run by a user with local access, potentially impacting all users on the host.

Remediation

Upgrade to a patched version of gotop once available, or remove the kill feature by disabling the process termination command. As an interim measure, run gotop under a restricted user account and restrict pkill usage via sudoers or container isolation. Monitor for unexpected process terminations.

Risk context

Severity is critical with CVSS 9.8 and low EPSS of 0.00154, indicating a high severity but low likelihood of exploitation in the wild. Defenders should treat it as a high-priority issue for systems running gotop.

Affected products

  • cjbassi/gotop 3.0.0
  • cjbassi/gotop

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.8
CVSS v4
4.8
EPSS
0.00154

argument-injection local-privilege-escalation process-termination gotop critical denial-of-service

← All CVEs