AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-73802.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces and execute commands on the runner host as root. ### Details Source-to-sink path in act_runner: - `ContainerSpec.Options` accepts workflow YAML `container.options` - `RunContext.options()` appends workflow options to runner-level container options - Job container is created with `Privileged: rc.Config.Privileged` but also with `Options: rc.options(ctx)` - `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig - When privileged mode is disabled, only `copts.privileged` is forced false - `sanitizeConfig()` only filters `Binds` and `Mounts` - Preserved dangerous HostConfig fields: ```text Privileged=false PidMode=host IpcMode=host CapAdd=["ALL"] SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] ``` Attacker workflow YAML: ```yaml jobs: breakout: runs-on: ubuntu-latest con

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-x4q3-gcj3-m6cf

Open original source · Updated Oct 02, 2026

gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
gogitea.com/gitea/runner< 1.0.9-0.20260731160927-34bfa19150221.0.9-0.20260731160927-34bfa1915022

Original records & references

PUBLISHED 2026-10-02T19:18:12-04:00
MODIFIED 2026-10-02T19:18:13-04:00
INGESTED 2026-10-06T11:45:17-04:00