CVE-2026-58053
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.4EPSS 0.3%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
28 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
Gitea · act_runnerpublic PoCs found — 1
cve_referencegithub.com/bikini/exploitarium/tree/main/gitea-act-runner-container-options-pocunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →