PT-2026-37316 · Ciguard · Ciguard

Published

2026-05-05

·

Updated

2026-05-12

·

CVE-2026-44220

CVSS v3.1

3.2

Low

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ciguard versions 0.8.0 through 0.8.1
Description The discover pipeline files() function in src/ciguard/discovery.py improperly handles symlinks when walking a directory tree. An attacker who can place a symlink in a directory being scanned can force the tool to access and return paths to files outside the intended root directory. This can lead to a confused-deputy scenario where an AI agent or user inadvertently exposes sensitive files, such as those in ~/.aws/, ~/.config/, or /etc/, which may contain hardcoded secrets, internal hostnames, or deploy keys.
Recommendations Update ciguard to version 0.8.2 or later. As a temporary workaround, restrict the tool from scanning directories containing untrusted symlinks.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44220
GHSA-8CXW-CC62-Q28V

Affected Products

Ciguard