criticalCVSS 9.9Vulnerability

CVE-2026-73802

### Summary act_runner appends workflow-controlled `jobs.<job>.container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces and execute commands on the runner host as root. ### Details Source-to-sink path in act_runner: - `ContainerSpec.Options` accepts workflow YAML `container.options` - `RunContext.options()` appends workflow options to runner-level container options - Job container is created with `Privileged: rc.Config.Privileged` but also with `Options: rc.options(ctx)` - `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig - When privileged mode is disabled, only `copts.privileged` is forced false - `sanitizeConfig()` only filters `Binds` and `Mounts` - Preserved dangerous HostConfig fields: ```text Privileged=false PidMode=host IpcMode=host CapAdd=["ALL"] SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] ``` Attacker workflow YAML: ```yaml jobs: breakout: runs-on: ubuntu-latest container: image: ubuntu:22.04 options: >- --pid=host --ipc=host --cap-add=ALL --security-opt seccomp=unconfined --security-opt apparmor=unconfined steps: - name: host namespace marker run: | nsenter -t 1 -m -u -i -n -p -- sh -c "id > /tmp/marker" ``` ### Impact An attacker who can submit a workflow to a repository using a shared Docker-backed act_runner can: - Enter host PID, IPC, and mount namespaces - Execute arbitrary commands as root on the runner host - Access runner host secrets, deployment credentials, and environment variables - Pivot to adjacent jobs running on the same runner - Access internal build infrastructure reachable from the runner host Critical severity for shared runners where

Properties

severity
critical
summary
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
cvss_score
9.9
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T23:18:12Z
source_url
https://github.com/advisories/GHSA-x4q3-gcj3-m6cf
ghsa_updated
2026-10-02T23:18:13Z
ghsa_id
GHSA-x4q3-gcj3-m6cf
last_source
GitHub Advisory Database
cve_id
CVE-2026-73802
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
false

Related Entities (4)

VULNERABLE_TO (1)

←[Software]go/gitea.com/gitea/runner

AFFECTS (1)

→[Software]go/gitea.com/gitea/runner

HAS_WEAKNESS (1)

→[Weakness]Improper Privilege Management

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph