<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Gitea-Runner (&lt; 1.0.9-0.20260731160927-34bfa1915022) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gitea-runner--1.0.9-0.20260731160927-34bfa1915022/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:50:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gitea-runner--1.0.9-0.20260731160927-34bfa1915022/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Gitea act_runner Container Escape via Unsanitized Workflow Options</title><link>https://feed.craftedsignal.io/briefs/2026-10-gitea-runner-container-escape/</link><pubDate>Sat, 03 Oct 2026 04:50:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gitea-runner-container-escape/</guid><description>An improper sanitization vulnerability in Gitea act_runner allows attackers to inject malicious Docker CLI flags into workflow container configurations, leading to full container escape and root-level command execution on the host.</description><content:encoded><![CDATA[<p>The Gitea act_runner (CVE-2026-73802) fails to properly sanitize the <code>container.options</code> field in workflow YAML files when privileged mode is disabled. While the runner forces the <code>Privileged</code> flag to false, it does not validate or strip other security-sensitive Docker HostConfig parameters. An attacker with the ability to trigger a workflow on a shared runner can supply custom Docker flags, such as <code>--pid=host</code>, <code>--ipc=host</code>, and various security profile overrides (e.g., <code>seccomp=unconfined</code>). These flags are merged into the container configuration, granting the job container broad access to the runner host's namespaces and resources. This vulnerability allows an attacker to escape the container, execute commands as root on the host, access host secrets, and pivot to other jobs running on the same infrastructure. The vulnerability affects versions of <code>gitea-runner</code> prior to 1.0.9-0.20260731160927-34bfa1915022.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker creates or modifies a workflow YAML file in a repository that triggers a Gitea act_runner.</li>
<li>Attacker defines a <code>container</code> block in the job specification including a malicious <code>options</code> field.</li>
<li>Attacker populates the <code>options</code> field with escape-enabling flags like <code>--pid=host</code>, <code>--ipc=host</code>, and <code>--cap-add=ALL</code>.</li>
<li>The Gitea runner parses the workflow and executes <code>mergeContainerConfigs()</code>, which incorporates these flags into the Docker HostConfig.</li>
<li>The runner initiates a Docker container using the malicious HostConfig, bypassing security constraints despite <code>privileged</code> mode being set to false.</li>
<li>The workflow job starts, and the attacker utilizes tools like <code>nsenter</code> to break out of the container namespace and gain shell access.</li>
<li>Attacker executes arbitrary commands with root privileges on the runner host to exfiltrate secrets or pivot to adjacent tasks.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full compromise of the runner host. In shared hosting environments, this allows attackers to access secrets, environment variables, and deployment credentials belonging to other users or jobs, and potentially penetrate internal build infrastructure reachable from the host.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Gitea act_runner to version 1.0.9-0.20260731160927-34bfa1915022 or later immediately to patch CVE-2026-73802.</li>
<li>Audit existing Gitea workflow files for usage of <code>container.options</code> that reference namespace or security capability flags.</li>
<li>Implement strict input validation on workflow runners to deny configurations that include <code>--pid=host</code>, <code>--ipc=host</code>, <code>--uts=host</code>, <code>--network=host</code>, or security-critical <code>seccomp</code>/<code>apparmor</code> overrides.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>