CVE-2026-100368: CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
### Impact An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers provided by the `CliInvoke.Specializations` package (the `PowershellProcessInvoker`/`CmdProcessInvoker` invokers, and the `UsePowerShell`/`UseCmd` middleware in v3 pre-release versions). The wrappers re-run a caller-supplied target and arguments inside a shell command (`pwsh -Command ...` / `cmd /c ...`). In affected versions the wrapped command was delivered to the operating system as a single `ProcessStartInfo.Arguments` string. The OS command-line parser re-tokenizes that string before the shell parses it, so a double quote (`"`) in the target or arguments breaks OS-level quoting and lets the wrapped shell reassemble a second, unintended command. An attacker could exploit this to execute arbitrary commands with the privileges of the host process. ### Patches The Specializations Packages now deliver the command via `ProcessStartInfo.ArgumentList` (natively where supported, and polyfilled in older TFMs), so that the operating system passes argv verbatim and only the shell parses the command once. Upgrade to: - **2.8.5** (2.8.x line) - **2.9.4** (2.9.x line) - **2.10.5** (2.10.x line) - **3.0.0-beta.1** (3.x pre-release line) ### Workarounds No complete workaround is available. Until upgraded: - Reject or strip `"` from any target path or argument passed to the PowerShell/Cmd wrappers. On 2.2.0 – 2.9.2 and 3.0.0-alpha.1 – alpha.4, also reject shell metacharacters (`;`, `|`, `&`, `$`, backtick, parentheses). - Alternatively, bypass the wrappers for untrusted input and invoke the target process directly so that no second shell parse of the data occurs.
Recommended action
Recommended action
Upgrade affected packages to a patched version: CliInvoke.Specializations 2.8.5, CliInvoke.Specializations 2.9.4, CliInvoke.Specializations 2.10.5, CliInvoke.Specializations 3.0.0-beta.1, CliInvoke.Specializations 3.0.0-beta.1, AlastairLundy.CliInvoke.Specializations 2.0.2.
Technical details
- Vendor
- Not specified
- Product
- CliInvoke.Specializations, AlastairLundy.CliInvoke.Specializations
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source