You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(security): [2.1] Fix PATH variable security issue in model detector
- Replace exec.CommandContext with 'which' command that relies on PATH variable
- Use fixed, secure paths to check for llama binary in common installation directories
- Only check predefined, unwriteable system directories: /usr/local/bin, /usr/bin, /opt/homebrew/bin, /opt/local/bin
- Remove dependency on os/exec package to eliminate PATH-based security risks
- Add binary_path metadata to track which secure path was used
- Fix test compilation error by using detector variable
Task: 2.1 - Fix PATH variable security vulnerability
Phase: Security
0 commit comments