Impact
The vulnerability is an instance of argument injection, where a process name is passed directly to the pkill utility without sanitization. A local attacker can craft a process name beginning with "--", causing pkill to interpret it as an option and terminate all processes owned by that user. The result is arbitrary termination of the victim user’s processes, effectively a denial‑of‑service condition. It falls under CWE‑88 and does not involve privilege escalation or code execution.
Affected Systems
The affected product is gotop developed by cjbassi. The issue was confirmed in version 3.0.0 and no fixes have been released because the project is no longer actively maintained. While other versions were not tested, they may also contain the flaw, so any system running gotop with the kill feature is considered vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not disclosed. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to the machine where gotop is installed. An attacker must be able to start a process with a crafted name and then invoke gotop’s kill functionality. Because it can only affect the local user’s processes, the overall risk to the organization is moderate but warrants action.
OpenCVE Enrichment