{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agiteagitea-runner/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gitea:gitea-runner:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gitea-runner (\u003c 1.0.9-0.20260731160927-34bfa1915022)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Gitea"],"content_html":"\u003cp\u003eThe Gitea act_runner (CVE-2026-73802) fails to properly sanitize the \u003ccode\u003econtainer.options\u003c/code\u003e field in workflow YAML files when privileged mode is disabled. While the runner forces the \u003ccode\u003ePrivileged\u003c/code\u003e flag to false, it does not validate or strip other security-sensitive Docker HostConfig parameters. An attacker with the ability to trigger a workflow on a shared runner can supply custom Docker flags, such as \u003ccode\u003e--pid=host\u003c/code\u003e, \u003ccode\u003e--ipc=host\u003c/code\u003e, and various security profile overrides (e.g., \u003ccode\u003eseccomp=unconfined\u003c/code\u003e). These flags are merged into the container configuration, granting the job container broad access to the runner host's namespaces and resources. This vulnerability allows an attacker to escape the container, execute commands as root on the host, access host secrets, and pivot to other jobs running on the same infrastructure. The vulnerability affects versions of \u003ccode\u003egitea-runner\u003c/code\u003e prior to 1.0.9-0.20260731160927-34bfa1915022.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates or modifies a workflow YAML file in a repository that triggers a Gitea act_runner.\u003c/li\u003e\n\u003cli\u003eAttacker defines a \u003ccode\u003econtainer\u003c/code\u003e block in the job specification including a malicious \u003ccode\u003eoptions\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eAttacker populates the \u003ccode\u003eoptions\u003c/code\u003e field with escape-enabling flags like \u003ccode\u003e--pid=host\u003c/code\u003e, \u003ccode\u003e--ipc=host\u003c/code\u003e, and \u003ccode\u003e--cap-add=ALL\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe Gitea runner parses the workflow and executes \u003ccode\u003emergeContainerConfigs()\u003c/code\u003e, which incorporates these flags into the Docker HostConfig.\u003c/li\u003e\n\u003cli\u003eThe runner initiates a Docker container using the malicious HostConfig, bypassing security constraints despite \u003ccode\u003eprivileged\u003c/code\u003e mode being set to false.\u003c/li\u003e\n\u003cli\u003eThe workflow job starts, and the attacker utilizes tools like \u003ccode\u003ensenter\u003c/code\u003e to break out of the container namespace and gain shell access.\u003c/li\u003e\n\u003cli\u003eAttacker executes arbitrary commands with root privileges on the runner host to exfiltrate secrets or pivot to adjacent tasks.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full compromise of the runner host. In shared hosting environments, this allows attackers to access secrets, environment variables, and deployment credentials belonging to other users or jobs, and potentially penetrate internal build infrastructure reachable from the host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Gitea act_runner to version 1.0.9-0.20260731160927-34bfa1915022 or later immediately to patch CVE-2026-73802.\u003c/li\u003e\n\u003cli\u003eAudit existing Gitea workflow files for usage of \u003ccode\u003econtainer.options\u003c/code\u003e that reference namespace or security capability flags.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on workflow runners to deny configurations that include \u003ccode\u003e--pid=host\u003c/code\u003e, \u003ccode\u003e--ipc=host\u003c/code\u003e, \u003ccode\u003e--uts=host\u003c/code\u003e, \u003ccode\u003e--network=host\u003c/code\u003e, or security-critical \u003ccode\u003eseccomp\u003c/code\u003e/\u003ccode\u003eapparmor\u003c/code\u003e overrides.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-03T04:50:09Z","date_published":"2026-10-03T04:50:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-gitea-runner-container-escape/","summary":"An improper sanitization vulnerability in Gitea act_runner allows attackers to inject malicious Docker CLI flags into workflow container configurations, leading to full container escape and root-level command execution on the host.","title":"Gitea act_runner Container Escape via Unsanitized Workflow Options","url":"https://feed.craftedsignal.io/briefs/2026-10-gitea-runner-container-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gitea:gitea-Runner:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}