# Unpatched argument injection flaw in gotop

Published: 2026-10-02 · Severity: routine
Canonical: https://vorant.io/reports/1ef14864-7900-5af4-bdfc-45491a42d8dc/unpatched-argument-injection-flaw-in-gotop

> CVE-2026-91784: gotop's process-kill feature passes unsanitized process names to pkill, letting a local attacker mass-kill another user's processes.

CERT Polska coordinated disclosure of CVE-2026-91784, a local argument injection vulnerability in cjbassi/gotop, a terminal-based system monitor. The flaw stems from gotop passing process names directly to the pkill command without sanitization when a user invokes the tool's kill functionality. A local attacker can create a process with a name beginning with '--' (for example embedding a target user's UID) so that when a gotop user attempts to terminate that process, pkill instead interprets the crafted name as a command-line argument, resulting in termination of all processes owned by the targeted user.

The vulnerability was confirmed in gotop version 3.0.0; other versions were not tested and may also be affected. The gotop project is no longer actively maintained and no fix has been released. Defenders running gotop should be aware there is no patch available and should consider removing or replacing the tool, restricting its use to trusted multi-user environments, or monitoring for anomalous process names beginning with '--' as a detection opportunity. The issue was reported by Michał Majchrowicz and Marcin Wyczechowski of AFINE Team.

## Mentioned in this report

- Vulnerabilities: CVE-2026-91784

## Detection guidance (public sample)

### gotop Spawning pkill With Option-Style Argument (CVE-2026-91784)

ATT&CK: T1059

gotop launching pkill with an argument beginning with '--' suggests a crafted process name is being parsed by pkill as an option (argument injection, CVE-2026-91784), e.g. --euid <uid> killing all of a user's processes. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: gotop Spawning pkill With Option-Style Argument (CVE-2026-91784)
id: a243d0b0-bed4-56cf-a2cb-b8353edfaf25
status: experimental
description: Detects gotop launching pkill where the command line contains a double-dash
  option. gotop passes the selected process name to pkill unsanitized, so a process
  named like '--euid 1000' is interpreted as an option and can kill every process
  of the targeted user (CVE-2026-91784). Matches the parent/child relation and option-style
  argument, not a specific UID.
tags:
- attack.execution
- attack.t1059
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    ParentImage|endswith: /gotop
    Image|endswith: /pkill
    CommandLine|contains: ' --'
  condition: selection
falsepositives:
- A gotop user or wrapper script deliberately passing pkill long options through a
  customised gotop build
- Administrators testing the kill function with unusual process names
level: high
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-91784
```

### Process Executed With Name or Argv0 Starting With Double Dash

ATT&CK: T1059

A process whose executable name or command line begins with '--' is a staging step for argument injection against tools such as gotop that pass process names to pkill. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Process Executed With Name or Argv0 Starting With Double Dash
id: 5ded9467-9fde-5d76-9854-cfc1303a212a
status: experimental
description: Detects Linux process creation where the executable file name or the
  start of the command line begins with a double dash. Attackers can craft such process
  names (for example embedding a target UID) so that a victim using gotop's kill function
  causes pkill to parse the name as an option (CVE-2026-91784). Legitimate software
  almost never runs with a name starting with '--'.
tags:
- attack.execution
- attack.t1059
logsource:
  category: process_creation
  product: linux
detection:
  selection_image:
    Image|contains: /--
  selection_cmd:
    CommandLine|startswith: --
  condition: 1 of selection_*
falsepositives:
- Wrapper scripts or test harnesses that invoke binaries with an argv0 beginning with
  dashes
- Login shells in some environments are exec'd with a leading single dash, which does
  not match this pattern but may indicate noisy collectors
level: medium
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-91784
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://cert.pl/en/posts/2026/10/CVE-2026-91784

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1ef14864-7900-5af4-bdfc-45491a42d8dc/unpatched-argument-injection-flaw-in-gotop.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
