Junglewise Threat Intelligence

CVE-2026-58053: Gitea act_runner container escape via Docker options injection

CVE-2026-58053 · Severity: critical · CVSS 9.9 · Published 2026-06-28

Vendors: Gitea.

Executive brief

Gitea act_runner is a component used to execute automated workflows (CI/CD) for Gitea repositories. A security flaw allows users who can submit workflows to bypass container security restrictions and gain full administrative (root) access to the underlying server hosting the runner. This could lead to the theft of sensitive credentials, exposure of source code, or a complete takeover of the build infrastructure.

Technical details

Gitea act_runner (through version 0.262.0) improperly handles the 'container.options' string in workflow YAML files when using the Docker backend. While the runner explicitly disables the 'Privileged' flag if configured to do so, it fails to filter other dangerous Docker HostConfig parameters such as '--pid=host', '--cap-add=ALL', and '--security-opt'. An attacker with permissions to trigger a workflow can provide these flags to gain host namespace access and elevated Linux capabilities. This enables a container escape to the host as root, even when the runner is explicitly configured with 'privileged: false'. A proof-of-concept exists demonstrating host access via 'nsenter' by entering host PID and IPC namespaces.

Affected products

  • Gitea act_runner <= 0.262.0

Timeline

  • 2026-06-27: disclosed: Vulnerability details and PoC published by VulnCheck/exploitarium.
  • 2026-06-28: advisory: NVD published CVE-2026-58053.

References