Vulnerability DatabaseCVE-2026-100368

CVE-2026-100368: 
C# vulnerability analysis and mitigation

Overview

CVE-2026-100368 is an OS command injection vulnerability (CWE-78) in the PowerShell and Cmd shell wrappers of the CliInvoke.Specializations and AlastairLundy.CliInvoke.Specializations NuGet packages for .NET. Affected versions include CliInvoke.Specializations 2.2.0–2.8.4, 2.9.0–2.9.3, 2.10.0–2.10.4, 3.0.0-alpha.1–3.0.0-alpha.4, and 3.0.0-alpha.8–3.0.0-alpha.10, as well as AlastairLundy.CliInvoke.Specializations 1.0.0-rc.1–1.6.1.1. The vulnerability was published by the repository maintainer on September 7, 2026, and added to the NVD on September 25, 2026. It carries a CVSS v3.1 base score of 8.4 (High) (GitHub Advisory, Security Advisory).

Technical details

The root cause is improper neutralization of special elements in OS commands (CWE-78). In affected versions, the PowershellProcessInvoker/CmdProcessInvoker invokers (and UsePowerShell/UseCmd middleware in v3 pre-releases) pass caller-controlled target paths and arguments to pwsh -Command or cmd /c as a single ProcessStartInfo.Arguments string. The OS command-line parser re-tokenizes this string before the shell processes it, so a double quote (") in untrusted input breaks OS-level quoting, allowing the shell to reassemble and execute a second, unintended command with the host process's privileges. The fix switches to ProcessStartInfo.ArgumentList, which passes argv verbatim so only the shell parses the command once, eliminating the double-parse injection vector (GitHub Advisory, Security Advisory).

Impact

Successful exploitation allows an attacker who can control the target path or arguments passed to the PowerShell or Cmd wrappers to inject and execute arbitrary OS commands with the privileges of the host process. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive data, modify or delete files, install malware, or disrupt service operation. The scope of impact depends on the privilege level of the hosting application; if the process runs with elevated rights, full system compromise is possible (GitHub Advisory, Security Advisory).

Exploitability

No public proof-of-concept exploit code is known, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.58% (46th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Exploitation steps

  1. Identify vulnerable applications: Locate .NET applications that use CliInvoke.Specializations or AlastairLundy.CliInvoke.Specializations in an affected version range and that pass user-controlled input to the PowershellProcessInvoker, CmdProcessInvoker, UsePowerShell, or UseCmd wrappers.
  2. Craft malicious input: Prepare a payload containing a double quote character (") to break OS-level argument quoting, followed by shell metacharacters and the desired injected command. For example, a target argument such as legitimate_arg" & malicious_command or legitimate_arg"; malicious_command (for older versions also susceptible to metacharacters like ;, |, &, $).
  3. Deliver the payload: Supply the crafted string as the target path or argument to the vulnerable wrapper — this could be via a web form, API parameter, configuration file, or any other input channel the application exposes that feeds into the CLI invocation.
  4. Trigger shell execution: When the application calls the wrapper, it constructs a single ProcessStartInfo.Arguments string such as pwsh -Command legitimate_arg" & malicious_command, which the OS re-tokenizes, breaking quoting and causing the shell to execute the injected command.
  5. Achieve code execution: The injected command runs with the privileges of the host .NET process, enabling actions such as data exfiltration, reverse shell establishment, or further lateral movement (GitHub Advisory, Security Advisory).

Indicators of compromise

  • Logs: Unexpected or anomalous PowerShell (pwsh) or cmd.exe process invocations in application or system event logs, particularly those containing double quotes, semicolons, pipes, or ampersands in command-line arguments; Windows Event ID 4688 (process creation) entries showing unusual child processes spawned by the .NET host process.
  • Process: Unusual child processes (e.g., powershell.exe, cmd.exe, net.exe, curl, wget, certutil) spawned by the application's .NET host process with unexpected arguments; processes making outbound network connections not typical for the application.
  • Network: Unexpected outbound connections from the application server to external IPs, particularly on common reverse shell ports (e.g., 4444, 1337, 8080); DNS queries for unfamiliar domains originating from the application process.
  • File System: Newly created scripts, executables, or web shells in application directories or temp folders; unexpected modifications to scheduled tasks, startup entries, or system binaries by the application process account.

Mitigation and workarounds

Upgrade to the patched versions immediately: CliInvoke.Specializations 2.8.5 (2.8.x line), 2.9.4 (2.9.x line), 2.10.5 (2.10.x line), or 3.0.0-beta.1 (3.x pre-release); and AlastairLundy.CliInvoke.Specializations 2.0.2. If upgrading is not immediately possible, reject or strip double quote characters (") from all target paths and arguments passed to the PowerShell/Cmd wrappers; for versions 2.2.0–2.9.2 and 3.0.0-alpha.1–3.0.0-alpha.4, also reject shell metacharacters (;, |, &, $, backtick, parentheses). As an alternative mitigation, bypass the PowerShell and Cmd wrappers entirely for untrusted input and invoke target processes directly via ProcessStartInfo without a shell intermediary (GitHub Advisory, Security Advisory).

Additional resources


Source: This report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-105794CRITICAL9.1
  • C# logoC#
  • Microsoft.Native.Quic.MsQuic.OpenSSL
NoYesOct 06, 2026
CVE-2026-105796HIGH8.8
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesOct 06, 2026
CVE-2026-100369HIGH8.4
  • C# logoC#
  • CliInvoke
NoYesSep 25, 2026
CVE-2026-100368HIGH8.4
  • C# logoC#
  • CliInvoke.Specializations
NoYesSep 25, 2026
CVE-2026-105795LOW3.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management