Skip to content
Threat Feed
critical advisory

Gitea act_runner Container Escape via Unsanitized Workflow Options

An improper sanitization vulnerability in Gitea act_runner allows attackers to inject malicious Docker CLI flags into workflow container configurations, leading to full container escape and root-level command execution on the host.

The Gitea act_runner (CVE-2026-73802) fails to properly sanitize the container.options field in workflow YAML files when privileged mode is disabled. While the runner forces the Privileged flag to false, it does not validate or strip other security-sensitive Docker HostConfig parameters. An attacker with the ability to trigger a workflow on a shared runner can supply custom Docker flags, such as --pid=host, --ipc=host, and various security profile overrides (e.g., seccomp=unconfined). These flags are merged into the container configuration, granting the job container broad access to the runner host's namespaces and resources. This vulnerability allows an attacker to escape the container, execute commands as root on the host, access host secrets, and pivot to other jobs running on the same infrastructure. The vulnerability affects versions of gitea-runner prior to 1.0.9-0.20260731160927-34bfa1915022.

Attack Chain

  1. Attacker creates or modifies a workflow YAML file in a repository that triggers a Gitea act_runner.
  2. Attacker defines a container block in the job specification including a malicious options field.
  3. Attacker populates the options field with escape-enabling flags like --pid=host, --ipc=host, and --cap-add=ALL.
  4. The Gitea runner parses the workflow and executes mergeContainerConfigs(), which incorporates these flags into the Docker HostConfig.
  5. The runner initiates a Docker container using the malicious HostConfig, bypassing security constraints despite privileged mode being set to false.
  6. The workflow job starts, and the attacker utilizes tools like nsenter to break out of the container namespace and gain shell access.
  7. Attacker executes arbitrary commands with root privileges on the runner host to exfiltrate secrets or pivot to adjacent tasks.

Impact

Successful exploitation results in full compromise of the runner host. In shared hosting environments, this allows attackers to access secrets, environment variables, and deployment credentials belonging to other users or jobs, and potentially penetrate internal build infrastructure reachable from the host.

Recommendation

  1. Upgrade Gitea act_runner to version 1.0.9-0.20260731160927-34bfa1915022 or later immediately to patch CVE-2026-73802.
  2. Audit existing Gitea workflow files for usage of container.options that reference namespace or security capability flags.
  3. Implement strict input validation on workflow runners to deny configurations that include --pid=host, --ipc=host, --uts=host, --network=host, or security-critical seccomp/apparmor overrides.

Immediate actions

Upgrade Gitea act_runner to 1.0.9-0.20260731160927-34bfa1915022 or later.

IT Operations 24h

Mitigations

Identify and block workflows utilizing container.options to configure host namespaces or capability expansion.

immediate Security Engineering

CVE-2026-73802