Skip to content

[sighthound] Security findings in github/gh-aw #67121

Description

@github-actions

Sighthound flagged these five Critical command injection findings (CWE-78) in the scan run. Review each input path and confirm whether untrusted values can control the executable or arguments.

  • pkg/cli/poutine.go:181 — Critical: exec.Command(localPath, args...). Constrain localPath to an expected executable and validate dynamic arguments while preserving argument boundaries.
  • pkg/cli/poutine.go:208 — Critical: exec.Command(dockerPath, dockerArgs...). Validate the Docker executable path and user-derived argument values; keep arguments as separate slice entries.
  • pkg/cli/runner_guard.go:122 — Critical: exec.Command(dockerPath, dockerArgs...). Verify the executable path and constrain dynamic Docker options and values before execution.
  • pkg/cli/grant.go:265 — Critical: exec.Command passes volumeMount, grantImageRef, containerPolicyPath, and imageRef. Validate these values against their expected formats and prevent them from changing the intended command structure.
  • pkg/cli/upgrade_command.go:490 — Critical: exec.Command(exe, newArgs...). Verify exe points to the intended upgraded binary and validate any arguments derived from untrusted input.

These are scanner findings for triage; confirm the input sources and reachability before changing behavior.

Generated by 🛡️ Sighthound Security Scan · codex · gpt60 · 12.3 AIC · ⌖ 5.31 AIC · ⊞ 12.2K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions