CVE-2026-58053: Gitea act_runner - Container Hardening Bypass via Workflow Container Options

Published Jun 28, 2026
·
Updated

Gitea actrunner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.

Affected Software

1 affected component
Gitea act_runner=0.262.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Gitea act_runner (Docker backend) to a version that resolves this vulnerability.

    Fixed in 0.262.0
  2. Compensating control

    For Docker-backed Gitea act_runner jobs, restrict workflow/container options so that user-controlled settings cannot add dangerous HostConfig options (e.g., --pid=host, --cap-add, or security-opt overrides) that allow namespace/capability escape even when privileged is configured as false.

Event History

Jun 28, 2026
CVE Published
via MITRE·01:32 AM
Data Sourced
via MITRE·01:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-58053?

CVE-2026-58053 has a critical severity rating of 9.9.

2

What types of systems are affected by CVE-2026-58053?

CVE-2026-58053 affects Gitea act_runner when utilizing the Docker backend.

3

How do I fix CVE-2026-58053?

To fix CVE-2026-58053, ensure that the configuration for the Gitea act_runner Docker backend does not allow unsafe container options.

4

What are the potential impacts of CVE-2026-58053?

The potential impacts of CVE-2026-58053 include an unauthorized bypass of container hardening measures, which can lead to container escape.

5

How can CVE-2026-58053 be exploited?

CVE-2026-58053 can be exploited by manipulating a workflow's container.options string to include unsafe Docker options when the container is run.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203