{"id":"GHSA-wrvw-254r-wpmv","summary":"CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers","details":"### Impact\nAn OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers provided by the `CliInvoke.Specializations` package (the `PowershellProcessInvoker`/`CmdProcessInvoker` invokers, and the `UsePowerShell`/`UseCmd` middleware in v3 pre-release versions).\n\nThe wrappers re-run a caller-supplied target and arguments inside a shell command (`pwsh -Command ...` / `cmd /c ...`). In affected versions the wrapped command was delivered to the operating system as a single `ProcessStartInfo.Arguments` string. The OS command-line parser re-tokenizes that string before the shell parses it, so a double quote (`\"`) in the target or arguments breaks OS-level quoting and lets the wrapped shell reassemble a second, unintended command. \n\nAn attacker could exploit this to execute arbitrary commands with the privileges of the host process.\n\n### Patches\nThe Specializations Packages now deliver the command via `ProcessStartInfo.ArgumentList` (natively where supported, and polyfilled in older TFMs), so that the operating system passes argv verbatim and only the shell parses the command once. \n\nUpgrade to:\n- **2.8.5** (2.8.x line)\n- **2.9.4** (2.9.x line)\n- **2.10.5** (2.10.x line)\n- **3.0.0-beta.1** (3.x pre-release line)\n\n### Workarounds\nNo complete workaround is available. Until upgraded:\n\n- Reject or strip `\"` from any target path or argument passed to the PowerShell/Cmd wrappers. On 2.2.0 – 2.9.2 and 3.0.0-alpha.1 – alpha.4, also reject shell metacharacters (`;`, `|`, `&`, `$`, backtick, parentheses).\n- Alternatively, bypass the wrappers for untrusted input and invoke the target process directly so that no second shell parse of the data occurs.","aliases":["CVE-2026-100368"],"modified":"2026-09-25T23:00:41.138516912Z","published":"2026-09-25T21:41:48Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-25T21:41:48Z","nvd_published_at":"2026-09-25T20:17:05Z","cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/alastairlundy/CliInvoke/security/advisories/GHSA-wrvw-254r-wpmv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100368"},{"type":"WEB","url":"https://github.com/alastairlundy/CliInvoke/commit/1e98582f02eb43e345e5b97b8dd6ff9443806685"},{"type":"WEB","url":"https://github.com/alastairlundy/CliInvoke/commit/2077e5239850e83dc9cc67ae6036dcd4e68a1876"},{"type":"PACKAGE","url":"https://github.com/alastairlundy/CliInvoke"},{"type":"WEB","url":"https://github.com/alastairlundy/CliInvoke/releases/tag/2.10.5"},{"type":"WEB","url":"https://github.com/alastairlundy/CliInvoke/releases/tag/3.0.0-beta.1"}],"affected":[{"package":{"name":"CliInvoke.Specializations","ecosystem":"NuGet","purl":"pkg:nuget/CliInvoke.Specializations"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.8.5"}]}],"versions":["2.2.0","2.2.1","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.6.1","2.7.0","2.7.1","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.8.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wrvw-254r-wpmv/GHSA-wrvw-254r-wpmv.json"}},{"package":{"name":"CliInvoke.Specializations","ecosystem":"NuGet","purl":"pkg:nuget/CliInvoke.Specializations"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.9.0"},{"fixed":"2.9.4"}]}],"versions":["2.9.1","2.9.2","2.9.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.9.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wrvw-254r-wpmv/GHSA-wrvw-254r-wpmv.json"}},{"package":{"name":"CliInvoke.Specializations","ecosystem":"NuGet","purl":"pkg:nuget/CliInvoke.Specializations"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.10.0"},{"fixed":"2.10.5"}]}],"versions":["2.10.0","2.10.2","2.10.3","2.10.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.10.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wrvw-254r-wpmv/GHSA-wrvw-254r-wpmv.json"}},{"package":{"name":"CliInvoke.Specializations","ecosystem":"NuGet","purl":"pkg:nuget/CliInvoke.Specializations"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-alpha.1"},{"fixed":"3.0.0-beta.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.0-alpha.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wrvw-254r-wpmv/GHSA-wrvw-254r-wpmv.json"}},{"package":{"name":"CliInvoke.Specializations","ecosystem":"NuGet","purl":"pkg:nuget/CliInvoke.Specializations"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-alpha.8"},{"fixed":"3.0.0-beta.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.0-alpha.10","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wrvw-254r-wpmv/GHSA-wrvw-254r-wpmv.json"}},{"package":{"name":"AlastairLundy.CliInvoke.Specializations","ecosystem":"NuGet","purl":"pkg:nuget/AlastairLundy.CliInvoke.Specializations"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0-rc.1"},{"fixed":"2.0.2"}]}],"versions":["1.0.0","1.1.0","1.2.0","1.2.1","1.3.0","1.3.1","1.4.1","1.4.3","1.4.4","1.4.5","1.5.1","1.5.2","1.6.0","1.6.1","1.6.1.1","2.0.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.6.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wrvw-254r-wpmv/GHSA-wrvw-254r-wpmv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}