PT-2026-104588 · Unknown · Act Runner

CVE-2026-73802

·

Published

2026-10-02

·

Updated

2026-10-03

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions act runner (affected versions not specified)
Description The act runner appends workflow-controlled jobs.<job>.container.options directly to the Docker HostConfig for the job container. When privileged mode is disabled, the system only forces the Privileged field to false, while preserving host namespace flags, capability expansion, and security profile overrides from the workflow YAML. This allows a workflow author to enter host PID and IPC namespaces and execute arbitrary commands as root on the runner host. This can lead to the exposure of runner host secrets, deployment credentials, and environment variables, as well as allowing the attacker to pivot to adjacent jobs or access internal build infrastructure.
Technical details include a source-to-sink path where ContainerSpec.Options accepts container.options from the YAML, which is then processed by RunContext.options() and mergeContainerConfigs(). The sanitizeConfig() function only filters Binds and Mounts, leaving dangerous fields such as PidMode=host, IpcMode=host, CapAdd=["ALL"], and SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] intact.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, treat container.options as untrusted input and restrict or strip the following options when privileged mode is disabled:
  • Host namespaces: --pid=host, --ipc=host, --uts=host, and --network=host
  • Capability expansion: --cap-add ALL and --cap-add SYS ADMIN
  • Security overrides: --security-opt seccomp=unconfined and --security-opt apparmor=unconfined
  • Device access: --device and --device-cgroup-rule
  • Volume inheritance: --volumes-from
  • Runtime controls: --runtime and --cgroup-parent

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73802
GHSA-X4Q3-GCJ3-M6CF

Affected Products

Act Runner