CVE-2026-91784 is a local argument-injection vulnerability in cjbassi/gotop's process-termination functionality. Gotop passes a selected process name directly to pkill without sanitization. An attacker can create a process with a name beginning with option delimiters and containing a target user's UID. If a gotop user selects that process and invokes the kill feature, pkill interprets the process name as a command-line option rather than solely as a process name.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local argument-injection vulnerability in cjbassi/gotop's process-termination feature. A crafted process name is passed unsanitized to pkill and interpreted as command-line options, enabling termination of all processes owned by an attacker-selected user when a gotop user chooses the crafted process for termination.
A local argument-injection vulnerability affecting the cjbassi/gotop software project.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.