nuget package report

Is CliInvoke.Specializations safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so nuget packages are not covered.


      cvss
      0.0
      high

      severity band, no base score published

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-wrvw-254r-wpmv, the advisory selected below

      // 1 advisories

      GHSA-wrvw-254r-wpmv

      HIGHCVE-2026-100368
      // impact

      An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers provided by the CliInvoke.Specializations package (the PowershellProcessInvoker/CmdProcessInvoker invokers, and the UsePowerShell/UseCmd middleware in v3 pre-release versions).

      The wrappers re-run a caller-supplied target and arguments inside a shell command (pwsh -Command ... / cmd /c ...). In affected versions the wrapped command was delivered to the operating system as a single ProcessStartInfo.Arguments string. The OS command-line parser re-tokenizes that string before the shell parses it, so a double quote (") in the target or arguments breaks OS-level quoting and lets the wrapped shell reassemble a second, unintended command.

      An attacker could exploit this to execute arbitrary commands with the privileges of the host process.

      // patches

      The Specializations Packages now deliver the command via ProcessStartInfo.ArgumentList (natively where supported, and polyfilled in older TFMs), so that the operating system passes argv verbatim and only the shell parses the command once.

      Upgrade to:

      • 2.8.5 (2.8.x line)
      • 2.9.4 (2.9.x line)
      • 2.10.5 (2.10.x line)
      • 3.0.0-beta.1 (3.x pre-release line)
      // workarounds

      No complete workaround is available. Until upgraded:

      • Reject or strip " from any target path or argument passed to the PowerShell/Cmd wrappers. On 2.2.0 – 2.9.2 and 3.0.0-alpha.1 – alpha.4, also reject shell metacharacters (;, |, &, $, backtick, parentheses).
      • Alternatively, bypass the wrappers for untrusted input and invoke the target process directly so that no second shell parse of the data occurs.

      Checked 2026-09-26 at 01:01 UTC. The most recent advisory here was published 2026-09-25. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.