CVE-2026-100369 is an argument-injection vulnerability in CliInvoke and AlastairLundy.CliInvoke .NET libraries. The vulnerability allows for potential arbitrary command execution when a shell runner is used. Affected versions include CliInvoke 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1, as well as AlastairLundy.CliInvoke 2.0.0-alpha.1 through 2. [truncated]
CVE-2026-100368 is an OS command injection vulnerability in CliInvoke.Specializations .NET library versions 2.2.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, 3.0.0-alpha.1 through 3.0.0-alpha.4, and 3.0.0-alpha.8 through 3.0.0-alpha.10, as well as AlastairLundy.CliInvoke.Specializations versions 1.0.0-rc.1 through 1.6.1.1. The vulnerability allows a double quote in untrusted input to break [truncated]