VYPR

gotop

by Cjbassi

CVEs (1)

  • CVE-2026-91784MedOct 2, 2026
    risk 0.31cvss —epss —

    cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID).…