Top Sighthound findings (from actionable.json):
/pkg/workflow/js/close_issue.cjs — Critical (Command Injection, CWE-78). User-controlled params taint reaches exec (line 53). Remediation: avoid shell execution for user input; use argument arrays (spawn/execFile) with strict allowlists and validation.
/pkg/workflow/js/close_issue.cjs — Critical (Command Injection, CWE-78). Taint flow to exec (line 6) in asShellArg path. Remediation: remove shell-string construction, use structured command invocation, and reject unsafe metacharacters.
/actions/setup/js/close_issue.cjs — Critical (Command Injection, CWE-78). User params reaches exec (line 53). Remediation: same hardening as above; centralize safe command wrapper and input schema checks.
/actions/setup/js/close_issue.cjs — Critical (Command Injection, CWE-78). Additional taint path to exec (line 6). Remediation: eliminate shell interpolation helpers and pass only validated, typed arguments.
/pkg/cli/bootstrap_profile_helpers.go — High (Code Injection/SSTI, CWE-94). Dynamic template parse via template.New(...).Parse(bootstrapRegistrationPageTmpl) (line 262). Remediation: keep templates static/embedded and pass untrusted values only as escaped data into template execution.
Notes:
- These were selected as the highest-severity findings (Critical/High) from
actionable.json.
- Prioritize fixing command-injection sinks first due to direct command execution risk.
Generated by 🛡️ Sighthound Security Scan · codex · gpt53codex · 6.21 AIC · ⌖ 2.67 AIC · ⊞ 18.6K · ◷
Top Sighthound findings (from actionable.json):
/pkg/workflow/js/close_issue.cjs— Critical (Command Injection, CWE-78). User-controlledparamstaint reachesexec(line 53). Remediation: avoid shell execution for user input; use argument arrays (spawn/execFile) with strict allowlists and validation./pkg/workflow/js/close_issue.cjs— Critical (Command Injection, CWE-78). Taint flow toexec(line 6) inasShellArgpath. Remediation: remove shell-string construction, use structured command invocation, and reject unsafe metacharacters./actions/setup/js/close_issue.cjs— Critical (Command Injection, CWE-78). Userparamsreachesexec(line 53). Remediation: same hardening as above; centralize safe command wrapper and input schema checks./actions/setup/js/close_issue.cjs— Critical (Command Injection, CWE-78). Additional taint path toexec(line 6). Remediation: eliminate shell interpolation helpers and pass only validated, typed arguments./pkg/cli/bootstrap_profile_helpers.go— High (Code Injection/SSTI, CWE-94). Dynamic template parse viatemplate.New(...).Parse(bootstrapRegistrationPageTmpl)(line 262). Remediation: keep templates static/embedded and pass untrusted values only as escaped data into template execution.Notes:
actionable.json.