Gitea act_runner Container Escape via Unsanitized Workflow Options
An improper sanitization vulnerability in Gitea act_runner allows attackers to inject malicious Docker CLI flags into workflow container configurations, leading to full container escape and root-level command execution on the host.
The Gitea act_runner (CVE-2026-73802) fails to properly sanitize the container.options field in workflow YAML files when privileged mode is disabled. While the runner forces the Privileged flag to false, it does not validate or strip other security-sensitive Docker HostConfig parameters. An attacker with the ability to trigger a workflow on a shared runner can supply custom Docker flags, such as --pid=host, --ipc=host, and various security profile overrides (e.g., seccomp=unconfined). These flags are merged into the container configuration, granting the job container broad access to the runner host's namespaces and resources. This vulnerability allows an attacker to escape the container, execute commands as root on the host, access host secrets, and pivot to other jobs running on the same infrastructure. The vulnerability affects versions of gitea-runner prior to 1.0.9-0.20260731160927-34bfa1915022.
Attack Chain
- Attacker creates or modifies a workflow YAML file in a repository that triggers a Gitea act_runner.
- Attacker defines a
containerblock in the job specification including a maliciousoptionsfield. - Attacker populates the
optionsfield with escape-enabling flags like--pid=host,--ipc=host, and--cap-add=ALL. - The Gitea runner parses the workflow and executes
mergeContainerConfigs(), which incorporates these flags into the Docker HostConfig. - The runner initiates a Docker container using the malicious HostConfig, bypassing security constraints despite
privilegedmode being set to false. - The workflow job starts, and the attacker utilizes tools like
nsenterto break out of the container namespace and gain shell access. - Attacker executes arbitrary commands with root privileges on the runner host to exfiltrate secrets or pivot to adjacent tasks.
Impact
Successful exploitation results in full compromise of the runner host. In shared hosting environments, this allows attackers to access secrets, environment variables, and deployment credentials belonging to other users or jobs, and potentially penetrate internal build infrastructure reachable from the host.
Recommendation
- Upgrade Gitea act_runner to version 1.0.9-0.20260731160927-34bfa1915022 or later immediately to patch CVE-2026-73802.
- Audit existing Gitea workflow files for usage of
container.optionsthat reference namespace or security capability flags. - Implement strict input validation on workflow runners to deny configurations that include
--pid=host,--ipc=host,--uts=host,--network=host, or security-criticalseccomp/apparmoroverrides.
Immediate actions
Upgrade Gitea act_runner to 1.0.9-0.20260731160927-34bfa1915022 or later.
Mitigations
Identify and block workflows utilizing container.options to configure host namespaces or capability expansion.
CVE-2026-73802