---
schema: 1
kind: vulnerability
title: "CVE-2026-58053 — Gitea act_runner Docker backend: container-hardening bypass to host escape (CVSS 9.4, public PoC)"
headline: "CVE-2026-58053 — Gitea act_runner Docker backend: container-hardening bypass to host escape (CVSS 9.4, public PoC)"
summary: "Gitea act_runner container-hardening bypass (CVE-2026-58053, CVSS 9.4, public PoC) lets any contributor with repo write access escape a privileged: false CI container to root on the host — self-hosted Gitea + Docker CI is common in Swiss/EU public-sector and academic IT (VulnCheck, 2026-06-27)."
discovered_at: "2026-06-28T05:05:38Z"
event_date: 2026-06-28
run_id: 2026-06-28-1b30612a
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - poc-public
  - priv-esc
  - rce
  - enisa-critical
regions:
  - global
  - europe
  - switzerland
sectors:
  - public-sector
  - education
  - technology
entities: []
cves:
  - id: CVE-2026-58053
    cvss: "9.4"
    epss: null
    type: priv-esc
    vector: user-interaction
    auth: post-auth
    status:
      - poc-public
      - enisa-critical
      - mitigation-only
sources:
  - url: "https://www.vulncheck.com/advisories/gitea-act-runner-container-hardening-bypass-via-workflow-container-options"
    publisher: VulnCheck advisory
    role: primary
  - url: "https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-58053"
    publisher: ENISA EUVD EUVD-2026-58053
    role: corroborating
closed_sources: []
evidence:
  - quote: "passes workflow container.options string to Docker job container HostConfig; forces only Privileged=false but merges options like --pid=host, --cap-add, --security-opt unchanged"
    publisher: VulnCheck
  - quote: "CVSS 4.0 score 9.4; public PoC"
    publisher: ENISA EUVD
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Constrain Gitea `act_runner` now** (§ 2, CVE-2026-58053): on Docker-backed runners, strip or allowlist `container.options` at the runner policy layer and require approval for external-contributor/fork workflow runs; upgrade to `act_runner >= 0.263.0` when released. Public PoC + CVSS 9.4 + the bypass specifically defeats the `privileged: false` hardening operators rely on."
migrated_from: briefs/2026-06-28.md
---

Gitea `act_runner` through 0.262.0 with the Docker backend passes the workflow-defined `container.options` string straight into Docker's `HostConfig` for the job container. When an operator hardens the runner with `privileged: false`, the code forces only the `Privileged` flag off but still merges the rest of `container.options` unchanged — so options such as `--pid=host`, `--cap-add=SYS_PTRACE`, `--security-opt=seccomp:unconfined` or arbitrary bind mounts pass through, allowing any user with write access to a repository whose workflows run on that runner to escape to the host as root despite the hardening ([VulnCheck, 2026-06-27](https://www.vulncheck.com/advisories/gitea-act-runner-container-hardening-bypass-via-workflow-container-options); [ENISA EUVD EUVD-2026-58053, 2026-06-28](https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-58053)). ENISA EUVD scores it CVSS 4.0 9.4 and a public PoC is referenced. Technique class: `T1611` Escape to Host via Docker HostConfig injection → `T1068`. Prerequisite is write access (or accepted external contribution) to a repo whose workflows execute on a Docker-backed runner configured `privileged: false` — the *common hardened* setting, which is what makes this dangerous. Self-service CI on internal Gitea + Docker is common in Swiss/EU public-sector and academic IT. Detection: watch Docker daemon audit logs for containers launched with unusual `HostConfig` flags (`pid_mode=host`, non-baseline `cap_add`, custom seccomp); review CI workflow-YAML diffs from external contributors for `container.options` injection. Mitigation now (vendor fix `act_runner >= 0.263.0` was pending at advisory time): strip or allowlist `container.options` at the runner policy layer, require approval for fork/external-contributor workflow runs, and use a kernel-isolation runtime (e.g. gVisor) for untrusted CI.
