Execution with Unnecessary Privileges Affecting ciguard package, versions [,0.8.2)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.12% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-CIGUARD-16428624
  • published6 May 2026
  • disclosed5 May 2026
  • creditUnknown

Introduced: 5 May 2026

CVE-2026-44218  (opens in a new tab)
CWE-250  (opens in a new tab)

How to fix?

Upgrade ciguard to version 0.8.2 or higher.

Overview

ciguard is a Static security auditor for CI/CD pipelines — now with a Model Context Protocol server (pip install 'ciguard[mcp]') exposing scan / scan_repo / explain_rule / diff_baseline / list_rules to Claude Desktop / Claude Code / Cursor. Plus .ciguardignore rationale-required suppression, baseline / delta reports, EOL-aware image checks, GitHub Actions CVE lookups across GitLab CI, GitHub Actions, and Jenkins Pipelines. Pre-commit hook + CIGUARD_MCP_DISABLED enterprise gate.

Affected versions of this package are vulnerable to Execution with Unnecessary Privileges due to the container image running as the root user by default, as the Dockerfile lacks a USER directive. An attacker can increase the impact of a potential container escape by leveraging root privileges within the container. This is only exploitable if a container escape vulnerability is present in the runtime environment.

CVSS Base Scores

version 4.0
version 3.1