PT-2026-37314 · Ciguard · Ciguard
Published
2026-05-05
·
Updated
2026-05-12
·
CVE-2026-44218
CVSS v3.1
3.0
Low
| Vector | AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ciguard versions 0.1.0 through 0.8.1
Description
The
ghcr.io/jo-jo98/ciguard container image inherits the default root user because the Dockerfile lacks a USER directive. As a static analyser, ciguard does not require root privileges. Running as root increases the potential impact of container-runtime escape vulnerabilities, where an attacker could potentially gain root access to the host system if a runtime vulnerability exists.Recommendations
Update to version 0.8.2 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ciguard