Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58053

Опубликовано: 28 июн. 2026
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.

EPSS

Процентиль: 18%
0.00265
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.9
debian
около 1 месяца назад

Gitea act_runner with the Docker backend (through act 0.262.0) passes ...

CVSS3: 9.9
github
около 1 месяца назад

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.

CVSS3: 9.9
fstec
около 1 месяца назад

Уязвимость компонента act_runner системы управления Git-репозиториями Gitea, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 18%
0.00265
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-269