Unpatched argument injection flaw in gotop
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CVE-2026-91784: gotop's process-kill feature passes unsanitized process names to pkill, letting a local attacker mass-kill another user's processes.
CERT Polska coordinated disclosure of CVE-2026-91784, a local argument injection vulnerability in cjbassi/gotop, a terminal-based system monitor. The flaw stems from gotop passing process names directly to the pkill command without sanitization when a user invokes the tool's kill functionality. A local attacker can create a process with a name beginning with '--' (for example embedding a target user's UID) so that when a gotop user attempts to terminate that process, pkill instead interprets the crafted name as a command-line argument, resulting in termination of all processes owned by the targeted user.
The vulnerability was confirmed in gotop version 3.0.0; other versions were not tested and may also be affected. The gotop project is no longer actively maintained and no fix has been released. Defenders running gotop should be aware there is no patch available and should consider removing or replacing the tool, restricting its use to trusted multi-user environments, or monitoring for anomalous process names beginning with '--' as a detection opportunity. The issue was reported by Michał Majchrowicz and Marcin Wyczechowski of AFINE Team.
Mentioned in this report
Detection guidance
gotop Spawning pkill With Option-Style Argument (CVE-2026-91784)
gotop launching pkill with an argument beginning with '--' suggests a crafted process name is being parsed by pkill as an option (argument injection, CVE-2026-91784), e.g. --euid <uid> killing all of a user's processes. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: gotop Spawning pkill With Option-Style Argument (CVE-2026-91784)
id: a243d0b0-bed4-56cf-a2cb-b8353edfaf25
status: experimental
description: Detects gotop launching pkill where the command line contains a double-dash
option. gotop passes the selected process name to pkill unsanitized, so a process
named like '--euid 1000' is interpreted as an option and can kill every process
of the targeted user (CVE-2026-91784). Matches the parent/child relation and option-style
argument, not a specific UID.
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: linux
detection:
selection:
ParentImage|endswith: /gotop
Image|endswith: /pkill
CommandLine|contains: ' --'
condition: selection
falsepositives:
- A gotop user or wrapper script deliberately passing pkill long options through a
customised gotop build
- Administrators testing the kill function with unusual process names
level: high
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-91784
Process Executed With Name or Argv0 Starting With Double Dash
A process whose executable name or command line begins with '--' is a staging step for argument injection against tools such as gotop that pass process names to pkill. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Process Executed With Name or Argv0 Starting With Double Dash
id: 5ded9467-9fde-5d76-9854-cfc1303a212a
status: experimental
description: Detects Linux process creation where the executable file name or the
start of the command line begins with a double dash. Attackers can craft such process
names (for example embedding a target UID) so that a victim using gotop's kill function
causes pkill to parse the name as an option (CVE-2026-91784). Legitimate software
almost never runs with a name starting with '--'.
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: linux
detection:
selection_image:
Image|contains: /--
selection_cmd:
CommandLine|startswith: --
condition: 1 of selection_*
falsepositives:
- Wrapper scripts or test harnesses that invoke binaries with an argv0 beginning with
dashes
- Login shells in some environments are exec'd with a leading single dash, which does
not match this pattern but may indicate noisy collectors
level: medium
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-91784
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://cert.pl/en/posts/2026/10/CVE-2026-91784
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,607 reports from 152 sources, 501 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs