Symlink Vulnerability in Ciguard CI/CD Static Security Auditor
CVE-2026-44220

3.2LOW

Key Information:

Vendor

Jo-jo98

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-44220?

Ciguard, a static security auditor designed for CI/CD pipelines, is affected by a vulnerability that arises from its discover_pipeline_files() function. In versions 0.8.0 to 0.8.1, the function traverses directory trees and follows symbolic links, potentially leading to unauthorized access to files outside the designated root directory. If an attacker is able to place a symlink within a scanned directory, they can manipulate the discovery process to unintentionally include paths to sensitive files. This issue has been addressed in version 0.8.2.

Affected Version(s)

ciguard >= 0.8.0, < 0.8.2

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.