CVE-2026-44220: ciguard symlink traversal exposes files outside scan root
The discover_pipeline_files() function in ciguard 0.8.0–0.8.1 follows symlinks when walking a directory tree, so an attacker who plants a symlink in a directory scanned by a user or AI agent can cause the tool to return paths to pipeline-shaped files outside the requested root. The issue is fixed in version 0.8.2.
Disclosed 12 May 2026 · Record updated 13 September 2026
Impact
Directory discovery can escape the requested root via attacker-planted symlinks, returning and potentially exposing pipeline files located outside the intended scan scope.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44220
