Vulnerability DatabaseCVE-2026-100369

CVE-2026-100369: 
C# vulnerability analysis and mitigation

Overview

CVE-2026-100369 is an argument injection vulnerability (CWE-88) in the CliInvoke and AlastairLundy.CliInvoke .NET libraries, which are used for invoking command-line programs and wrapping executable processes. The flaw exists in the RunnerProcessFactory (2.x line) and RunnerConfigurationFactory (3.x line) factory classes, which concatenate runner arguments, caller-controlled targets, and caller-controlled arguments into a single ProcessStartInfo.Arguments string without proper escaping. Affected versions include CliInvoke 2.0.0–2.8.4, 2.9.0–2.9.3, 2.10.0–2.10.4, and 3.0.0-alpha.1–3.0.0-beta.1, as well as AlastairLundy.CliInvoke 2.0.0-alpha.1–2.0.0. The vulnerability was published on September 25, 2026, and carries a CVSS v3.1 base score of 8.4 (High) (GitHub Advisory).

Technical details

The root cause (CWE-88: Improper Neutralization of Argument Delimiters in a Command) lies in how the factory classes build the OS-level command string: runner arguments, the caller-supplied target path, and caller-supplied arguments are all joined into one ProcessStartInfo.Arguments string and handed to the OS for re-tokenization. A double quote (") embedded in the target path or any argument terminates the OS-level quoted region prematurely, allowing subsequent characters to be interpreted as separate, unintended argument tokens. When a shell runner (e.g., cmd.exe or pwsh.exe) is used, this argument vector manipulation can escalate to arbitrary command execution by injecting shell metacharacters such as ;, |, &, or $(). The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), making it exploitable by any local process or user that can influence the target or argument strings passed to the factory (GitHub Advisory, Patch Commit).

Impact

Successful exploitation can result in arbitrary command execution on the host system, with confidentiality, integrity, and availability all rated High. An unauthenticated local attacker who can control the target path or arguments passed to the vulnerable factory methods can inject OS commands that execute in the context of the calling process, potentially enabling data exfiltration, file system modification, or denial of service. The risk is greatest when shell runners (cmd.exe, pwsh.exe) are used, as shell metacharacters in injected tokens are interpreted as additional commands (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The CVE status is listed as "Deferred" and the NVD SSVC assessment confirms exploitation is "none" and the vulnerability is not automatable. The EPSS score is approximately 0.0036 (0.36%), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a vulnerable application: Locate a .NET application that uses CliInvoke (versions 2.0.0–2.8.4, 2.9.0–2.9.3, 2.10.0–2.10.4, or 3.0.0-alpha.1–3.0.0-beta.1) or AlastairLundy.CliInvoke (2.0.0-alpha.1–2.0.0) and passes caller-controlled input to RunnerProcessFactory.CreateRunnerConfiguration() or RunnerConfigurationFactory.CreateRunnerConfiguration().
  2. Craft a malicious target or argument string: Prepare a string containing a double quote (") to terminate the OS-level quoted region, followed by shell metacharacters and a payload command. For example, a target path like app.exe" & calc.exe or an argument like safe" & malicious_command.
  3. Inject via the factory: Supply the crafted string as the TargetFilePath or Arguments field of the ProcessConfiguration passed to the vulnerable factory. The factory concatenates all values into a single ProcessStartInfo.Arguments string without sanitization.
  4. Trigger shell execution: Ensure the application uses a shell runner (e.g., cmd.exe or pwsh.exe). When the process is launched, the OS re-tokenizes the combined argument string, and the injected double quote breaks the quoted region, causing the shell to interpret the injected metacharacters as additional commands.
  5. Achieve arbitrary command execution: The injected command executes in the context of the calling process's user account, enabling actions such as spawning a reverse shell, exfiltrating data, or modifying files (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Process: Unexpected child processes spawned by a .NET application using CliInvoke, such as cmd.exe, pwsh.exe, calc.exe, or other binaries not normally invoked by the application; processes with unusual argument strings containing shell metacharacters (&, |, ;, $().
  • Logs: Application or system logs showing process launches with argument strings containing double quotes followed by shell operators; Windows Event Log entries (Event ID 4688) for unexpected process creation chains originating from the affected .NET application.
  • File System: Unexpected files created or modified in directories accessible to the application's service account; new scripts or executables dropped by child processes of the .NET application.
  • Network: Outbound connections from the .NET application process or its child processes to unexpected external hosts, which may indicate reverse shell or data exfiltration activity.

Mitigation and workarounds

Upgrade to the patched versions: CliInvoke 2.8.5, 2.9.4, 2.10.5, or 3.0.0-beta.2; or AlastairLundy.CliInvoke 2.0.2. The fix replaces single-string argument concatenation with discrete argument tokenization using a new ArgumentTokenizer class, and delivers tokens via ProcessStartInfo.ArgumentList on supported runtimes (NET 8.0+), preventing OS-level re-parsing (Release 2.10.5, Patch Commit). If an immediate upgrade is not possible, apply these partial mitigations: (1) strip all double quotes from targets and arguments before passing them to the factory; (2) when using shell runners, also strip shell metacharacters (;, |, &, $, backtick, parentheses); or (3) bypass the factory entirely and construct a ProcessConfiguration directly with an explicit ArgumentList (GitHub Advisory).

Community reactions

The vulnerability was published by the library author (alastairlundy) via a GitHub Security Advisory and coordinated through GitHub's security advisory process. Social media activity was limited, with brief mentions on Bluesky and Mastodon from automated CVE tracking accounts. No significant independent researcher commentary or major media coverage has been identified for this vulnerability.

Additional resources


Source: This report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-105794CRITICAL9.1
  • C# logoC#
  • Microsoft.Native.Quic.MsQuic.OpenSSL
NoYesOct 06, 2026
CVE-2026-105796HIGH8.8
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesOct 06, 2026
CVE-2026-100369HIGH8.4
  • C# logoC#
  • CliInvoke
NoYesSep 25, 2026
CVE-2026-100368HIGH8.4
  • C# logoC#
  • CliInvoke.Specializations
NoYesSep 25, 2026
CVE-2026-105795LOW3.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management