Critical severity9.9NVD Advisory· Published Jun 28, 2026· Updated Jun 30, 2026
CVE-2026-58053
CVE-2026-58053
Description
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.