CVE-2026-58053
CRITICALGitea act_runner - Container Hardening Bypass via Workflow Container Options
Title source: cnaDescription
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
References (2)
Core 2
Core References
Exploit exploit
third-party-advisory
Proof of Concept
https://github.com/bikini/exploitarium/tree/main/gitea-act-runner-container-options-poc
Third Party Advisory third-party-advisory
VulnCheck Advisory: Gitea act_runner - Container Hardening Bypass via Workflow Container Options
https://www.vulncheck.com/advisories/gitea-act-runner-container-hardening-bypass-via-workflow-container-options
Scores
CVSS v3
9.9
EPSS
0.0027
EPSS Percentile
18.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (1)
Gitea/act_runner
< 0.262.0
Published
Jun 28, 2026
Tracked Since
Jun 28, 2026