{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aalastair_lundycliinvoke/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:alastair_lundy:cliinvoke:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-100369"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CliInvoke (\u003e= 2.0.0, \u003c= 2.8.4)","CliInvoke (\u003e= 2.9.0, \u003c= 2.9.3)","CliInvoke (\u003e= 2.10.0, \u003c= 2.10.4)","CliInvoke (\u003e= 3.0.0-alpha.1, \u003c= 3.0.0-beta.1)","AlastairLundy.CliInvoke (\u003e= 2.0.0-alpha.1, \u003c= 2.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Alastair Lundy"],"content_html":"\u003cp\u003eThe CliInvoke package, used for extensibility and runner management, contains an argument-injection vulnerability (CVE-2026-100369) within its process factory components, specifically the \u003ccode\u003eRunnerProcessFactory\u003c/code\u003e (2.x versions) and the \u003ccode\u003eRunnerConfigurationFactory\u003c/code\u003e (3.x versions). The vulnerability stems from the way these factories join runner arguments, targets, and caller arguments into a single string for \u003ccode\u003eProcessStartInfo.Arguments\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eWhen this string is passed to the operating system, the command-line parser re-tokenizes it. Because the library fails to sanitize input, an attacker can embed double quotes (\u003ccode\u003e\u0026quot;\u003c/code\u003e) into a target or argument to close the intended quoted region prematurely. This allows subsequent characters to be interpreted by the OS as separate command-line arguments, potentially resulting in arbitrary command execution. This flaw affects multiple versions of \u003ccode\u003eCliInvoke\u003c/code\u003e and \u003ccode\u003eAlastairLundy.CliInvoke\u003c/code\u003e. Defenders should prioritize upgrading to the patched versions specified in the remediation section.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for argument injection, which can be leveraged to execute arbitrary commands or manipulate program flow within the context of the calling application. This vulnerability impacts any application using the affected \u003ccode\u003eCliInvoke\u003c/code\u003e libraries to execute external processes with user-supplied input. There are currently no reports of widespread in-the-wild exploitation, but the ease of triggering this via malicious input makes it a significant risk for enterprise applications utilizing this library.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003eCliInvoke\u003c/code\u003e package to the patched versions immediately: 2.8.5, 2.9.4, 2.10.5, or 3.0.0-beta.2.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing \u003ccode\u003eCliInvoke\u003c/code\u003e for user-controllable input that is passed to the \u003ccode\u003eRunnerProcessFactory\u003c/code\u003e or \u003ccode\u003eRunnerConfigurationFactory\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAs a temporary mitigation, implement strict input validation to strip double quotes (\u003ccode\u003e\u0026quot;\u003c/code\u003e) from all target and argument strings before they are passed to the factory.\u003c/li\u003e\n\u003cli\u003eIf using shell runners, also strip common shell meta-characters including \u003ccode\u003e;\u003c/code\u003e, \u003ccode\u003e|\u003c/code\u003e, \u003ccode\u003e\u0026amp;\u003c/code\u003e, \u003ccode\u003e$\u003c/code\u003e, backticks, and parentheses.\u003c/li\u003e\n\u003cli\u003eTransition to building \u003ccode\u003eProcessConfiguration\u003c/code\u003e objects directly by setting \u003ccode\u003eArgumentList\u003c/code\u003e explicitly, which avoids the flawed string concatenation approach used by the factory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T02:07:19Z","date_published":"2026-09-26T02:07:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cliinvoke-argument-injection/","summary":"The CliInvoke NuGet package is vulnerable to argument injection due to improper sanitization when constructing process arguments, potentially allowing attackers to execute arbitrary commands by manipulating command-line tokens.","title":"Argument Injection in CliInvoke Extensibility Runner Factory","url":"https://feed.craftedsignal.io/briefs/2026-09-cliinvoke-argument-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:alastair_lundy:cliinvoke:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}