Threat Advisory

Gitea Runner Flaw Lets Attackers Enter Host Namespaces and Execute Commands as Root

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting gitea.com/gitea/runner versions < 1.0.9-0.20260731160927-34bfa1915022 (CVE-2026-73802) exists in the gitea-runner package, allowing an attacker to enter host namespaces and execute commands as root on the runner host. This occurs when privileged mode is disabled, enabling untrusted users to trigger workflows using a shared Docker-backed act_runner. The flaw arises from the workflow-controlled container.options being appended directly to the Docker HostConfig for the job container, preserving host namespace flags, capability expansion, and security profile overrides from the workflow YAML. An attacker who can submit a workflow to a repository can enter host PID, IPC, and mount namespaces, execute arbitrary commands as root on the runner host, access runner host secrets, deployment credentials, and environment variables, pivot to adjacent jobs running on the same runner, and access internal build infrastructure reachable from the runner host. This vulnerability has a CVSS v3 score of 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) and is considered critical for shared runners where untrusted users can trigger workflows, as well as high severity for single-tenant runners with privileged mode explicitly disabled as a security control.

RECOMMENDATION:

We recommend you to update gitea-runner to version 1.0.9-0.20260731160927-34bfa1915022.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting gitea.com/gitea/runner versions < 1.0.9-0.20260731160927-34bfa1915022 (CVE-2026-73802) exists in the gitea-runner package, allowing an attacker to enter host namespaces and execute commands as root on the runner host. This occurs when privileged mode is disabled, enabling untrusted users to trigger workflows using a shared Docker-backed act_runner. The flaw arises from the workflow-controlled container.options being appended directly to the Docker HostConfig for the job container, preserving host namespace flags, capability expansion, and security profile overrides from the workflow YAML. An attacker who can submit a workflow to a repository can enter host PID, IPC, and mount namespaces, execute arbitrary commands as root on the runner host, access runner host secrets, deployment credentials, and environment variables, pivot to adjacent jobs running on the same runner, and access internal build infrastructure reachable from the runner host. This vulnerability has a CVSS v3 score of 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) and is considered critical for shared runners where untrusted users can trigger workflows, as well as high severity for single-tenant runners with privileged mode explicitly disabled as a security control.

RECOMMENDATION:

We recommend you to update gitea-runner to version 1.0.9-0.20260731160927-34bfa1915022.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu