CVE-2026-100369 | AlastairLundy CliInvoke/AlastairLundy.CliInvoke up to 2.0.0 Process Factory RunnerProcessFactory/RunnerConfigurationFactory os command injection

SecurityVulns

A vulnerability marked as problematic has been reported in AlastairLundy CliInvoke and AlastairLundy.CliInvoke up to 2.8.4/2.9.3/2.10.4/3.0.0-beta.1/2.0.0. This impacts the function RunnerProcessFactory/RunnerConfigurationFactory of the component Process Factory. Performing a manipulation results in os command injection.

This vulnerability was named CVE-2026-100369. The attack needs to be approached locally. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More