{"id":"CVE-2026-73802","aliases":["GHSA-x4q3-gcj3-m6cf"],"title":"gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled","summary":"gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled","severity":"critical","cvss":9.9,"cwe":["CWE-269"],"vendor":"gitea","product":"gitea.com/gitea/runner","ecosystem":"go","affected":["gitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022"],"patched":["gitea.com/gitea/runner 1.0.9-0.20260731160927-34bfa1915022"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T23:18:13Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-x4q3-gcj3-m6cf","references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-x4q3-gcj3-m6cf"},{"url":"https://gitea.com/gitea/runner/pulls/1058"},{"url":"https://gitea.com/gitea/runner/releases/tag/v3.0.0"},{"url":"https://github.com/advisories/GHSA-x4q3-gcj3-m6cf"}],"tags":["ghsa","go"],"ingestedAt":"2026-10-02T23:34:57.388Z","slug":"CVE-2026-73802","body":"## Overview\n\n### Summary\nact_runner appends workflow-controlled `jobs.<job>.container.options` directly \nto the Docker HostConfig for the job container. When runner privileged mode is \ndisabled, only `Privileged` is forced false. Host namespace flags, capability \nexpansion, and security profile overrides from workflow YAML are preserved in \nthe final HostConfig. A workflow author can enter host PID/IPC namespaces and \nexecute commands on the runner host as root.\n\n### Details\nSource-to-sink path in act_runner:\n\n- `ContainerSpec.Options` accepts workflow YAML `container.options`\n- `RunContext.options()` appends workflow options to runner-level container options\n- Job container is created with `Privileged: rc.Config.Privileged` but also \n  with `Options: rc.options(ctx)`\n- `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig\n- When privileged mode is disabled, only `copts.privileged` is forced false\n- `sanitizeConfig()` only filters `Binds` and `Mounts`\n- Preserved dangerous HostConfig fields:\n\n```text\nPrivileged=false\nPidMode=host\nIpcMode=host\nCapAdd=[\"ALL\"]\nSecurityOpt=[\"seccomp=unconfined\",\"apparmor=unconfined\"]\n```\n\nAttacker workflow YAML:\n```yaml\njobs:\n  breakout:\n    runs-on: ubuntu-latest\n    container:\n      image: ubuntu:22.04\n      options: >-\n        --pid=host --ipc=host --cap-add=ALL \n        --security-opt seccomp=unconfined \n        --security-opt apparmor=unconfined\n    steps:\n      - name: host namespace marker\n        run: |\n          nsenter -t 1 -m -u -i -n -p -- sh -c \"id > /tmp/marker\"\n```\n\n### Impact\nAn attacker who can submit a workflow to a repository using a shared \nDocker-backed act_runner can:\n\n- Enter host PID, IPC, and mount namespaces\n- Execute arbitrary commands as root on the runner host\n- Access runner host secrets, deployment credentials, and environment variables\n- Pivot to adjacent jobs running on the same runner\n- Access internal build infrastructure reachable from the runner host\n\nCritical severity for shared runners where untrusted users can trigger \nworkflows. High severity for single-tenant runners with privileged mode \nexplicitly disabled as a security control.\n\n### Fix Direction\nTreat `container.options` as untrusted input. Reject or strip when \nprivileged mode is disabled:\n\n- Host namespaces: `--pid=host`, `--ipc=host`, `--uts=host`, `--network=host`\n- Capability expansion: `--cap-add ALL`, `--cap-add SYS_ADMIN`\n- Security overrides: `--security-opt seccomp=unconfined`, `--security-opt apparmor=unconfined`\n- Device access: `--device`, `--device-cgroup-rule`\n- Volume inheritance: `--volumes-from`\n- Runtime controls: `--runtime`, `--cgroup-parent`\n\n## Affected packages\n\n- `gitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gitea.com/gitea/runner 1.0.9-0.20260731160927-34bfa1915022`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":54.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}