Sighthound flagged these five Critical findings in the actionable scan output. Review input handling and reachability before treating them as confirmed vulnerabilities.
| Path |
Severity |
Remediation guidance |
pkg/cli/poutine.go:132 (runPoutineOnDirectory) |
Critical |
Validate the directory used for the Docker volume mount; keep executable and arguments fixed and separately passed. |
pkg/cli/poutine.go:256 (runPoutineOnFile) |
Critical |
Validate the file-derived Docker volume mount; reject unexpected paths and keep arguments separately passed. |
pkg/cli/runner_guard.go:122 |
Critical |
Review how dockerPath and dockerArgs are built; allow only expected options and validated path inputs. |
pkg/cli/grant.go:265 |
Critical |
Validate imageRef and mount inputs before invoking Docker; keep arguments in a fixed, separate argument list. |
pkg/cli/upgrade_command.go:490 |
Critical |
Constrain the executable and forwarded arguments when relaunching; reject unexpected dynamic values. |
Source: Sighthound actionable findings from workflow run 37732213928.
Generated by 🛡️ Sighthound Security Scan · codex · gpt60 · 11.7 AIC · ⌖ 5.27 AIC · ⊞ 12.2K · ◷
Sighthound flagged these five Critical findings in the actionable scan output. Review input handling and reachability before treating them as confirmed vulnerabilities.
pkg/cli/poutine.go:132(runPoutineOnDirectory)pkg/cli/poutine.go:256(runPoutineOnFile)pkg/cli/runner_guard.go:122dockerPathanddockerArgsare built; allow only expected options and validated path inputs.pkg/cli/grant.go:265imageRefand mount inputs before invoking Docker; keep arguments in a fixed, separate argument list.pkg/cli/upgrade_command.go:490Source: Sighthound actionable findings from workflow run 37732213928.