CVE-2026-100369

Source
https://cve.org/CVERecord?id=CVE-2026-100369
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100369.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100369
Aliases
Published
2026-09-25T20:26:51Z
Modified
2026-09-26T11:45:38Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CliInvoke: Argument Injection in Extensibility Runner Factory
Details

CliInvoke and its formerly named AlastairLundy.CliInvoke package are .NET libraries for invoking command-line programs and wrapping executable processes. CliInvoke versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1, as well as AlastairLundy.CliInvoke versions 2.0.0-alpha.1 through 2.0.0, contain an argument-injection vulnerability in RunnerProcessFactory on the 2.x line and RunnerConfigurationFactory on the 3.x line. These factories combine runner arguments, a caller-controlled target, and caller-controlled arguments into one ProcessStartInfo.Arguments string, allowing a double quote in the target or an argument to terminate an operating-system-level quoted region and inject unintended elements into the runner’s argument vector, potentially resulting in arbitrary command execution when a shell runner is used. The vulnerability is patched in CliInvoke versions 2.8.5, 2.9.4, 2.10.5, and 3.0.0-beta.2, and in AlastairLundy.CliInvoke version 2.0.2. No complete workaround is available; users unable to upgrade can partially mitigate the issue by removing double quotes from targets and arguments, additionally removing shell metacharacters when using shell runners, or bypassing the vulnerable factory and constructing a ProcessConfiguration with an explicit ArgumentList.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-88"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100369.json"
}
References

Affected packages

Git / github.com/alastairlundy/cliinvoke

Affected ranges

Type
GIT
Repo
https://github.com/alastairlundy/cliinvoke
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.0.0"
        },
        {
            "last_affected":  "2.8.4"
        },
        {
            "introduced":  "2.9.0"
        },
        {
            "last_affected":  "2.9.3"
        },
        {
            "introduced":  "2.10.0"
        },
        {
            "last_affected":  "2.10.4"
        },
        {
            "introduced":  "3.0.0-alpha.1"
        },
        {
            "last_affected":  "3.0.0-beta.1"
        },
        {
            "introduced":  "2.0.0-alpha.1"
        },
        {
            "last_affected":  "2.0.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

2.*
2.0.0
2.1.0
2.1.1
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.2.0-alpha.1
2.2.0-alpha.2
2.2.0-beta.1
2.2.0-rc.1
2.2.0-v2
2.3.0
2.3.0-alpha.1
2.3.0-alpha.2
2.3.0-alpha.3
2.3.0-beta.1
2.4.0
2.4.0-alpha.1
2.4.0-alpha.2
2.4.0-beta.1
2.5.0
2.5.0-alpha.1
2.5.0-beta.1
2.5.1
2.5.2
2.6.0
2.7.0
2.7.0-alpha.1
2.7.0-beta.1
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.9.0
2.9.1
2.9.2
2.9.3
3.*
3.0.0-alpha.1
3.0.0-alpha.10
3.0.0-alpha.2
3.0.0-alpha.3
3.0.0-alpha.4
3.0.0-alpha.5
3.0.0-alpha.6
3.0.0-alpha.7
3.0.0-alpha.8
3.0.0-alpha.9
3.0.0-beta.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100369.json"