CERT Polska disclosed CVE-2026-91784, a local argument-injection flaw in cjbassi/gotop version 3.0.0. Gotop’s process-termination feature passes a selected process name to pkill without sanitization. A local attacker can create a process with a name beginning with -- that embeds a target user’s UID; when a gotop user selects that process for termination, pkill can interpret the name as a command-line option and terminate all processes owned by the target user.
The issue was reported by Michał Majchrowicz and Marcin Wyczechowski of AFINE Team and coordinated by CERT Polska. The product is unsupported and no fix is available; other untested releases may also be affected. Organizations using gotop should remove or restrict its process-killing capability, replace it with a maintained alternative, and assess exposure on multi-user systems where local users can create attacker-controlled process names.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
CERT Polska published CVE-2026-91784, a CWE-88 local argument-injection vulnerability confirmed in gotop 3.0.0. Crafted process names beginning with "--" can be passed unsanitized to pkill through gotop's process-termination feature, potentially causing termination of all processes owned by a targeted user; the unsupported product has no fix available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.