PT-2026-37314 · Ciguard · Ciguard

Published

2026-05-05

·

Updated

2026-05-12

·

CVE-2026-44218

CVSS v3.1

3.0

Low

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ciguard versions 0.1.0 through 0.8.1
Description The ghcr.io/jo-jo98/ciguard container image inherits the default root user because the Dockerfile lacks a USER directive. As a static analyser, ciguard does not require root privileges. Running as root increases the potential impact of container-runtime escape vulnerabilities, where an attacker could potentially gain root access to the host system if a runtime vulnerability exists.
Recommendations Update to version 0.8.2 or later.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44218
GHSA-JRM4-4PCF-4763

Affected Products

Ciguard