Gitea act_runner with the Docker backend (through act 0...
Critical severity
Unreviewed
Published
Jun 28, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jun 28, 2026
Published to the GitHub Advisory Database
Jun 28, 2026
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
References