PT-2026-104588 · Unknown · Act Runner
CVE-2026-73802
·
Published
2026-10-02
·
Updated
2026-10-03
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
act runner (affected versions not specified)
Description
The
act runner appends workflow-controlled jobs.<job>.container.options directly to the Docker HostConfig for the job container. When privileged mode is disabled, the system only forces the Privileged field to false, while preserving host namespace flags, capability expansion, and security profile overrides from the workflow YAML. This allows a workflow author to enter host PID and IPC namespaces and execute arbitrary commands as root on the runner host. This can lead to the exposure of runner host secrets, deployment credentials, and environment variables, as well as allowing the attacker to pivot to adjacent jobs or access internal build infrastructure.Technical details include a source-to-sink path where
ContainerSpec.Options accepts container.options from the YAML, which is then processed by RunContext.options() and mergeContainerConfigs(). The sanitizeConfig() function only filters Binds and Mounts, leaving dangerous fields such as PidMode=host, IpcMode=host, CapAdd=["ALL"], and SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] intact.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, treat
container.options as untrusted input and restrict or strip the following options when privileged mode is disabled:- Host namespaces:
--pid=host,--ipc=host,--uts=host, and--network=host - Capability expansion:
--cap-add ALLand--cap-add SYS ADMIN - Security overrides:
--security-opt seccomp=unconfinedand--security-opt apparmor=unconfined - Device access:
--deviceand--device-cgroup-rule - Volume inheritance:
--volumes-from - Runtime controls:
--runtimeand--cgroup-parent
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Act Runner