PT-2026-99117 · Cliinvoke · Cliinvoke
CVE-2026-100369
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CliInvoke versions 2.0.0 through 2.8.4
CliInvoke versions 2.9.0 through 2.9.3
CliInvoke versions 2.10.0 through 2.10.4
CliInvoke versions 3.0.0-alpha.1 through 3.0.0-beta.1
AlastairLundy.CliInvoke versions 2.0.0-alpha.1 through 2.0.0
Description
An argument-injection issue exists in the
RunnerProcessFactory (on the 2.x line) and RunnerConfigurationFactory (on the 3.x line). These factories combine runner arguments, a caller-controlled target, and caller-controlled arguments into a single ProcessStartInfo.Arguments string. Because the operating system command-line parser re-tokenizes this string, a double quote in the target or an argument can terminate the quoted region and inject unintended elements into the argument vector. This can lead to arbitrary command execution when a shell runner is used.Recommendations
Update CliInvoke versions 2.0.0 through 2.8.4 to 2.8.5.
Update CliInvoke versions 2.9.0 through 2.9.3 to 2.9.4.
Update CliInvoke versions 2.10.0 through 2.10.4 to 2.10.5.
Update CliInvoke versions 3.0.0-alpha.1 through 3.0.0-beta.1 to 3.0.0-beta.2.
Update AlastairLundy.CliInvoke versions 2.0.0-alpha.1 through 2.0.0 to 2.0.2.
As a partial mitigation, remove double quotes from targets and arguments, and remove shell metacharacters (
;, |, &, $, backticks, and parentheses) when using shell runners.
As an alternative mitigation, bypass the vulnerable factory and construct a ProcessConfiguration by explicitly setting the ArgumentList.Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cliinvoke