Skip to content

gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled

Critical severity GitHub Reviewed Published Aug 15, 2026 in go-gitea/gitea • Updated Oct 2, 2026

Package

gomod gitea.com/gitea/runner (Go)

Affected versions

< 1.0.9-0.20260731160927-34bfa1915022

Patched versions

1.0.9-0.20260731160927-34bfa1915022

Description

Summary

act_runner appends workflow-controlled jobs.<job>.container.options directly
to the Docker HostConfig for the job container. When runner privileged mode is
disabled, only Privileged is forced false. Host namespace flags, capability
expansion, and security profile overrides from workflow YAML are preserved in
the final HostConfig. A workflow author can enter host PID/IPC namespaces and
execute commands on the runner host as root.

Details

Source-to-sink path in act_runner:

  • ContainerSpec.Options accepts workflow YAML container.options
  • RunContext.options() appends workflow options to runner-level container options
  • Job container is created with Privileged: rc.Config.Privileged but also
    with Options: rc.options(ctx)
  • mergeContainerConfigs() parses Docker CLI-style options into HostConfig
  • When privileged mode is disabled, only copts.privileged is forced false
  • sanitizeConfig() only filters Binds and Mounts
  • Preserved dangerous HostConfig fields:
Privileged=false
PidMode=host
IpcMode=host
CapAdd=["ALL"]
SecurityOpt=["seccomp=unconfined","apparmor=unconfined"]

Attacker workflow YAML:

jobs:
  breakout:
    runs-on: ubuntu-latest
    container:
      image: ubuntu:22.04
      options: >-
        --pid=host --ipc=host --cap-add=ALL 
        --security-opt seccomp=unconfined 
        --security-opt apparmor=unconfined
    steps:
      - name: host namespace marker
        run: |
          nsenter -t 1 -m -u -i -n -p -- sh -c "id > /tmp/marker"

Impact

An attacker who can submit a workflow to a repository using a shared
Docker-backed act_runner can:

  • Enter host PID, IPC, and mount namespaces
  • Execute arbitrary commands as root on the runner host
  • Access runner host secrets, deployment credentials, and environment variables
  • Pivot to adjacent jobs running on the same runner
  • Access internal build infrastructure reachable from the runner host

Critical severity for shared runners where untrusted users can trigger
workflows. High severity for single-tenant runners with privileged mode
explicitly disabled as a security control.

Fix Direction

Treat container.options as untrusted input. Reject or strip when
privileged mode is disabled:

  • Host namespaces: --pid=host, --ipc=host, --uts=host, --network=host
  • Capability expansion: --cap-add ALL, --cap-add SYS_ADMIN
  • Security overrides: --security-opt seccomp=unconfined, --security-opt apparmor=unconfined
  • Device access: --device, --device-cgroup-rule
  • Volume inheritance: --volumes-from
  • Runtime controls: --runtime, --cgroup-parent

References

@bircni bircni published to go-gitea/gitea Aug 15, 2026
Published to the GitHub Advisory Database Oct 2, 2026
Reviewed Oct 2, 2026
Last updated Oct 2, 2026

Severity

Critical

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS score

Weaknesses

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. Learn more on MITRE.

CVE ID

CVE-2026-73802

GHSA ID

GHSA-x4q3-gcj3-m6cf

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.