{"id":"GHSA-x4q3-gcj3-m6cf","summary":"gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled","details":"### Summary\nact_runner appends workflow-controlled `jobs.\u003cjob\u003e.container.options` directly \nto the Docker HostConfig for the job container. When runner privileged mode is \ndisabled, only `Privileged` is forced false. Host namespace flags, capability \nexpansion, and security profile overrides from workflow YAML are preserved in \nthe final HostConfig. A workflow author can enter host PID/IPC namespaces and \nexecute commands on the runner host as root.\n\n### Details\nSource-to-sink path in act_runner:\n\n- `ContainerSpec.Options` accepts workflow YAML `container.options`\n- `RunContext.options()` appends workflow options to runner-level container options\n- Job container is created with `Privileged: rc.Config.Privileged` but also \n  with `Options: rc.options(ctx)`\n- `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig\n- When privileged mode is disabled, only `copts.privileged` is forced false\n- `sanitizeConfig()` only filters `Binds` and `Mounts`\n- Preserved dangerous HostConfig fields:\n\n```text\nPrivileged=false\nPidMode=host\nIpcMode=host\nCapAdd=[\"ALL\"]\nSecurityOpt=[\"seccomp=unconfined\",\"apparmor=unconfined\"]\n```\n\nAttacker workflow YAML:\n```yaml\njobs:\n  breakout:\n    runs-on: ubuntu-latest\n    container:\n      image: ubuntu:22.04\n      options: \u003e-\n        --pid=host --ipc=host --cap-add=ALL \n        --security-opt seccomp=unconfined \n        --security-opt apparmor=unconfined\n    steps:\n      - name: host namespace marker\n        run: |\n          nsenter -t 1 -m -u -i -n -p -- sh -c \"id \u003e /tmp/marker\"\n```\n\n### Impact\nAn attacker who can submit a workflow to a repository using a shared \nDocker-backed act_runner can:\n\n- Enter host PID, IPC, and mount namespaces\n- Execute arbitrary commands as root on the runner host\n- Access runner host secrets, deployment credentials, and environment variables\n- Pivot to adjacent jobs running on the same runner\n- Access internal build infrastructure reachable from the runner host\n\nCritical severity for shared runners where untrusted users can trigger \nworkflows. High severity for single-tenant runners with privileged mode \nexplicitly disabled as a security control.\n\n### Fix Direction\nTreat `container.options` as untrusted input. Reject or strip when \nprivileged mode is disabled:\n\n- Host namespaces: `--pid=host`, `--ipc=host`, `--uts=host`, `--network=host`\n- Capability expansion: `--cap-add ALL`, `--cap-add SYS_ADMIN`\n- Security overrides: `--security-opt seccomp=unconfined`, `--security-opt apparmor=unconfined`\n- Device access: `--device`, `--device-cgroup-rule`\n- Volume inheritance: `--volumes-from`\n- Runtime controls: `--runtime`, `--cgroup-parent`","aliases":["CVE-2026-73802"],"modified":"2026-10-02T23:30:07.701701193Z","published":"2026-10-02T23:18:12Z","database_specific":{"cwe_ids":["CWE-269"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-10-02T23:18:12Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-x4q3-gcj3-m6cf"},{"type":"WEB","url":"https://gitea.com/gitea/runner/pulls/1058"},{"type":"WEB","url":"https://gitea.com/gitea/runner/releases/tag/v3.0.0"},{"type":"PACKAGE","url":"https://github.com/go-gitea/gitea"}],"affected":[{"package":{"name":"gitea.com/gitea/runner","ecosystem":"Go","purl":"pkg:golang/gitea.com/gitea/runner"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.9-0.20260731160927-34bfa1915022"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-x4q3-gcj3-m6cf/GHSA-x4q3-gcj3-m6cf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}