PT-2026-99117 · Cliinvoke · Cliinvoke

CVE-2026-100369

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CliInvoke versions 2.0.0 through 2.8.4 CliInvoke versions 2.9.0 through 2.9.3 CliInvoke versions 2.10.0 through 2.10.4 CliInvoke versions 3.0.0-alpha.1 through 3.0.0-beta.1 AlastairLundy.CliInvoke versions 2.0.0-alpha.1 through 2.0.0
Description An argument-injection issue exists in the RunnerProcessFactory (on the 2.x line) and RunnerConfigurationFactory (on the 3.x line). These factories combine runner arguments, a caller-controlled target, and caller-controlled arguments into a single ProcessStartInfo.Arguments string. Because the operating system command-line parser re-tokenizes this string, a double quote in the target or an argument can terminate the quoted region and inject unintended elements into the argument vector. This can lead to arbitrary command execution when a shell runner is used.
Recommendations Update CliInvoke versions 2.0.0 through 2.8.4 to 2.8.5. Update CliInvoke versions 2.9.0 through 2.9.3 to 2.9.4. Update CliInvoke versions 2.10.0 through 2.10.4 to 2.10.5. Update CliInvoke versions 3.0.0-alpha.1 through 3.0.0-beta.1 to 3.0.0-beta.2. Update AlastairLundy.CliInvoke versions 2.0.0-alpha.1 through 2.0.0 to 2.0.2. As a partial mitigation, remove double quotes from targets and arguments, and remove shell metacharacters (;, |, &, $, backticks, and parentheses) when using shell runners. As an alternative mitigation, bypass the vulnerable factory and construct a ProcessConfiguration by explicitly setting the ArgumentList.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100369
GHSA-J73W-8HFR-4GC9

Affected Products

Cliinvoke