Sighthound flagged these five Critical command injection findings (CWE-78) in the scan run. Review each input path and confirm whether untrusted values can control the executable or arguments.
pkg/cli/poutine.go:181 — Critical: exec.Command(localPath, args...). Constrain localPath to an expected executable and validate dynamic arguments while preserving argument boundaries.
pkg/cli/poutine.go:208 — Critical: exec.Command(dockerPath, dockerArgs...). Validate the Docker executable path and user-derived argument values; keep arguments as separate slice entries.
pkg/cli/runner_guard.go:122 — Critical: exec.Command(dockerPath, dockerArgs...). Verify the executable path and constrain dynamic Docker options and values before execution.
pkg/cli/grant.go:265 — Critical: exec.Command passes volumeMount, grantImageRef, containerPolicyPath, and imageRef. Validate these values against their expected formats and prevent them from changing the intended command structure.
pkg/cli/upgrade_command.go:490 — Critical: exec.Command(exe, newArgs...). Verify exe points to the intended upgraded binary and validate any arguments derived from untrusted input.
These are scanner findings for triage; confirm the input sources and reachability before changing behavior.
Generated by 🛡️ Sighthound Security Scan · codex · gpt60 · 12.3 AIC · ⌖ 5.31 AIC · ⊞ 12.2K · ◷
Sighthound flagged these five Critical command injection findings (CWE-78) in the scan run. Review each input path and confirm whether untrusted values can control the executable or arguments.
pkg/cli/poutine.go:181— Critical:exec.Command(localPath, args...). ConstrainlocalPathto an expected executable and validate dynamic arguments while preserving argument boundaries.pkg/cli/poutine.go:208— Critical:exec.Command(dockerPath, dockerArgs...). Validate the Docker executable path and user-derived argument values; keep arguments as separate slice entries.pkg/cli/runner_guard.go:122— Critical:exec.Command(dockerPath, dockerArgs...). Verify the executable path and constrain dynamic Docker options and values before execution.pkg/cli/grant.go:265— Critical:exec.CommandpassesvolumeMount,grantImageRef,containerPolicyPath, andimageRef. Validate these values against their expected formats and prevent them from changing the intended command structure.pkg/cli/upgrade_command.go:490— Critical:exec.Command(exe, newArgs...). Verifyexepoints to the intended upgraded binary and validate any arguments derived from untrusted input.These are scanner findings for triage; confirm the input sources and reachability before changing behavior.