CVE-2026-100369
Description
CliInvoke and its formerly named AlastairLundy.CliInvoke package are .NET libraries for invoking command-line programs and wrapping executable processes. CliInvoke versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1, as well as AlastairLundy.CliInvoke versions 2.0.0-alpha.1 through 2.0.0, contain an argument-injection vulnerability in RunnerProcessFactory on the 2.x line and RunnerConfigurationFactory on the 3.x line. These factories combine runner arguments, a caller-controlled target, and caller-controlled arguments into one ProcessStartInfo.Arguments string, allowing a double quote in the target or an argument to terminate an operating-system-level quoted region and inject unintended elements into the runner’s argument vector, potentially resulting in arbitrary command execution when a shell runner is used. The vulnerability is patched in CliInvoke versions 2.8.5, 2.9.4, 2.10.5, and 3.0.0-beta.2, and in AlastairLundy.CliInvoke version 2.0.2. No complete workaround is available; users unable to upgrade can partially mitigate the issue by removing double quotes from targets and arguments, additionally removing shell metacharacters when using shell runners, or bypassing the vulnerable factory and constructing a ProcessConfiguration with an explicit ArgumentList.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 2.0.0-alpha.1 through 2.0.0, 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, 3.0.0-alpha.1 through 3.0.0-beta.1
- Range: 2.0.0-alpha.1 through 2.0.0, 2.0.2
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-j73w-8hfr-4gc9ghsaADVISORY
- github.com/alastairlundy/CliInvoke/commit/1e98582f02eb43e345e5b97b8dd6ff9443806685ghsa
- github.com/alastairlundy/CliInvoke/commit/fac321c7cc9cf4372919842701829ca2be5e7307ghsa
- github.com/alastairlundy/CliInvoke/releases/tag/2.10.5ghsa
- github.com/alastairlundy/CliInvoke/releases/tag/3.0.0-beta.2ghsa
- github.com/alastairlundy/CliInvoke/security/advisories/GHSA-j73w-8hfr-4gc9nvd
- nvd.nist.gov/vuln/detail/CVE-2026-100369ghsa
News mentions
0No linked articles in our index yet.