PT-2026-99106 · Unknown · Cliinvoke.Specializations+1
CVE-2026-100368
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CliInvoke.Specializations versions 2.2.0 through 2.8.4
CliInvoke.Specializations versions 2.9.0 through 2.9.3
CliInvoke.Specializations versions 2.10.0 through 2.10.4
CliInvoke.Specializations versions 3.0.0-alpha.1 through 3.0.0-alpha.4
CliInvoke.Specializations versions 3.0.0-alpha.8 through 3.0.0-alpha.10
AlastairLundy.CliInvoke.Specializations versions 1.0.0-rc.1 through 1.6.1.1
Description
An OS command injection issue exists in the PowerShell and Cmd shell wrappers, specifically within the
PowershellProcessInvoker and CmdProcessInvoker invokers, and the UsePowerShell and UseCmd middleware. The wrappers pass a caller-controlled target and arguments to pwsh -Command or cmd /c using a single ProcessStartInfo.Arguments string. Because the OS command-line parser re-tokenizes this string before the shell parses it, a double quote in untrusted input can break operating-system-level quoting. This allows the shell to execute additional, unintended commands with the privileges of the host process.Recommendations
Update CliInvoke.Specializations versions 2.2.0 through 2.8.4 to version 2.8.5.
Update CliInvoke.Specializations versions 2.9.0 through 2.9.3 to version 2.9.4.
Update CliInvoke.Specializations versions 2.10.0 through 2.10.4 to version 2.10.5.
Update CliInvoke.Specializations versions 3.0.0-alpha.1 through 3.0.0-alpha.10 to version 3.0.0-beta.1.
Update AlastairLundy.CliInvoke.Specializations versions 1.0.0-rc.1 through 1.6.1.1 to version 2.0.2.
As a temporary mitigation, reject or remove double quotes from target paths and arguments.
For CliInvoke.Specializations versions 2.2.0 through 2.9.2 and 3.0.0-alpha.1 through 3.0.0-alpha.4, reject shell metacharacters such as
;, |, &, $, backticks, and parentheses.
Bypass the PowerShell and Cmd wrappers and invoke target processes directly when handling untrusted input.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alastairlundy.Cliinvoke.Specializations
Cliinvoke.Specializations