
PEACH
Un cadre d’isolation des locataires
CVE-2026-73802 is a critical privilege escalation vulnerability in Gitea's act_runner (the Gitea Actions runner) that allows a workflow author to escape the job container and execute arbitrary commands as root on the runner host. The vulnerability affects gitea.com/gitea/runner versions prior to 1.0.9-0.20260731160927-34bfa1915022 (pre-release) and below 3.0.0 (stable). It was first published on August 15, 2026, and added to the GitHub Advisory Database on October 2, 2026. It carries a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, Gitea Security Advisory).
The root cause is improper privilege management (CWE-269) in how act_runner processes the workflow-controlled jobs.<job>.container.options field. The ContainerSpec.Options value is passed through RunContext.options() and appended to runner-level container options, then parsed by mergeContainerConfigs() into a Docker HostConfig struct. When privileged mode is disabled, sanitizeConfig() only strips Binds and Mounts, and only copts.privileged is forced to false — leaving dangerous fields such as PidMode=host, IpcMode=host, CapAdd=["ALL"], and SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] intact in the final HostConfig. An attacker can craft a workflow YAML with container.options containing flags like --pid=host --ipc=host --cap-add=ALL --security-opt seccomp=unconfined to achieve a full container breakout (GitHub Advisory, Gitea Security Advisory).
A successful exploit allows an attacker to enter the host PID, IPC, and mount namespaces and execute arbitrary commands as root on the runner host. This results in full confidentiality, integrity, and availability compromise of the runner host — including access to runner host secrets, deployment credentials, and environment variables. The attacker can also pivot to adjacent jobs running on the same shared runner and reach internal build infrastructure accessible from the runner network. The impact is rated Critical for shared runners where untrusted users can trigger workflows, and High for single-tenant runners where privileged mode was explicitly disabled as a security control (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory publication date, and the CVE status remains "Reserved" in the NVD. The Feedly threat intelligence data shows no recorded exploitation events (exploitedAt: []) and no listed PoCs (proofOfConcepts: []). The vulnerability requires only low privileges (the ability to submit a workflow to a repository using a shared Docker-backed runner), making it accessible to any contributor or collaborator on a Gitea instance. It is not currently listed in the CISA KEV catalog (GitHub Advisory, Gitea Security Advisory).
act_runner instance with privileged mode disabled..gitea/workflows/breakout.yml) with a job that specifies a container with dangerous options:jobs:
breakout:
runs-on: ubuntu-latest
container:
image: ubuntu:22.04
options: >-
--pid=host --ipc=host --cap-add=ALL
--security-opt seccomp=unconfined
--security-opt apparmor=unconfined
steps:
- name: host namespace marker
run: |
nsenter -t 1 -m -u -i -n -p -- sh -c "id > /tmp/marker"HostConfig fields (PidMode=host, IpcMode=host, CapAdd=["ALL"], security profiles unconfined), allowing nsenter to enter the host's PID/mount/network namespaces./etc/shadow, exfiltrate environment variables containing secrets, install a backdoor, or pivot to internal infrastructure) (GitHub Advisory, Gitea Security Advisory).container.options in workflow YAML files containing flags such as --pid=host, --ipc=host, --uts=host, --network=host, --cap-add=ALL, --cap-add=SYS_ADMIN, --security-opt seccomp=unconfined, or --security-opt apparmor=unconfined.PidMode=host, IpcMode=host, or CapAdd=["ALL"] visible in docker inspect output or container runtime logs.nsenter invocations as child processes of the runner's Docker container entrypoint; processes with host PID namespace visibility (e.g., seeing host init process PID 1 from within the container)./tmp/marker or similar artifacts) by the runner service account; new cron jobs, SSH keys, or backdoors placed on the runner host.container.options values containing namespace or capability flags; audit logs (auditd) recording nsenter or unshare syscalls from the runner process tree.Upgrade gitea.com/gitea/runner to version 3.0.0 or later (stable), or to the pre-release commit 1.0.9-0.20260731160927-34bfa1915022 or later, which treats container.options as untrusted input and strips dangerous flags when privileged mode is disabled. The fix rejects or sanitizes host namespace flags (--pid=host, --ipc=host, --uts=host, --network=host), capability expansion (--cap-add ALL, --cap-add SYS_ADMIN), security profile overrides (--security-opt seccomp=unconfined, --security-opt apparmor=unconfined), device access, volume inheritance, and runtime controls. As a short-term workaround, restrict who can submit workflows to shared runners, or run each workflow in an isolated single-tenant runner environment. The patch is tracked in Gitea runner pull request #1058 and the v3.0.0 release (GitHub Advisory, Gitea Security Advisory).
The vulnerability was reported by security researcher sn0x-sharma and published by bircni to the go-gitea/gitea repository on August 15, 2026, with the GitHub Advisory Database entry added on October 2, 2026. No significant public commentary, media coverage, or social media discussion has been identified beyond the advisory itself as of the available data (GitHub Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."