CVE-2026-91784 gotop 参数注入漏洞
影响本地攻击者可终止目标用户的全部进程
gotop 是 cjbassi 开发的终端系统监控工具,其进程终止功能在调用 pkill 时未对进程名做任何过滤。本地攻击者可创建一个以 -- 开头、包含目标用户 UID 的进程名,诱导运行 gotop 的用户对该进程执行 kill 操作,从而触发参数注入。
影响范围
受影响组件为 cjbassi/gotop,已在 3.0.0 版本确认存在该漏洞;其他版本未测试但可能同样受影响。该产品已停止维护,漏洞未修复。
漏洞详情
漏洞类型为本地参数注入。gotop 在实现终止进程功能时,将进程名直接拼接进 pkill 命令,未做转义或参数分隔处理。当进程名以 -- 开头时,pkill 会将其解析为命令行选项而非进程名,例如可借 --uid 等参数匹配并终止指定用户拥有的所有进程。
利用条件与风险
利用前提是攻击者能在本地创建具有特制名称的进程,且运行 gotop 的用户对该进程执行 kill 操作。成功利用可导致目标用户会话内所有进程被强制终止,造成拒绝服务,但需本地交互条件,整体风险中等。
修复建议
该产品已停止维护,官方未提供修复版本,暂无公开补丁信息。临时缓解措施包括:避免使用 gotop 的进程终止功能,或改用仍在维护的替代监控工具(如 btop、htop)。
cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with — (e.g. containing a target user’s UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user.
Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.