PT-2026-99106 · Unknown · Cliinvoke.Specializations+1

CVE-2026-100368

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CliInvoke.Specializations versions 2.2.0 through 2.8.4 CliInvoke.Specializations versions 2.9.0 through 2.9.3 CliInvoke.Specializations versions 2.10.0 through 2.10.4 CliInvoke.Specializations versions 3.0.0-alpha.1 through 3.0.0-alpha.4 CliInvoke.Specializations versions 3.0.0-alpha.8 through 3.0.0-alpha.10 AlastairLundy.CliInvoke.Specializations versions 1.0.0-rc.1 through 1.6.1.1
Description An OS command injection issue exists in the PowerShell and Cmd shell wrappers, specifically within the PowershellProcessInvoker and CmdProcessInvoker invokers, and the UsePowerShell and UseCmd middleware. The wrappers pass a caller-controlled target and arguments to pwsh -Command or cmd /c using a single ProcessStartInfo.Arguments string. Because the OS command-line parser re-tokenizes this string before the shell parses it, a double quote in untrusted input can break operating-system-level quoting. This allows the shell to execute additional, unintended commands with the privileges of the host process.
Recommendations Update CliInvoke.Specializations versions 2.2.0 through 2.8.4 to version 2.8.5. Update CliInvoke.Specializations versions 2.9.0 through 2.9.3 to version 2.9.4. Update CliInvoke.Specializations versions 2.10.0 through 2.10.4 to version 2.10.5. Update CliInvoke.Specializations versions 3.0.0-alpha.1 through 3.0.0-alpha.10 to version 3.0.0-beta.1. Update AlastairLundy.CliInvoke.Specializations versions 1.0.0-rc.1 through 1.6.1.1 to version 2.0.2. As a temporary mitigation, reject or remove double quotes from target paths and arguments. For CliInvoke.Specializations versions 2.2.0 through 2.9.2 and 3.0.0-alpha.1 through 3.0.0-alpha.4, reject shell metacharacters such as ;, |, &, $, backticks, and parentheses. Bypass the PowerShell and Cmd wrappers and invoke target processes directly when handling untrusted input.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100368
GHSA-WRVW-254R-WPMV

Affected Products

Alastairlundy.Cliinvoke.Specializations
Cliinvoke.Specializations