🔴 严重 | CVE-2026-58053 — Gitea act_runner with the Docker backend (through act 0
🔴 《严重安全漏洞:CVE-2026-58053》
CVSS 评分: 严重(9.4) CVE ID: CVE-2026-58053
漏洞描述
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
| 字段 | 值 |
|---|---|
| CVE ID | CVE-2026-58053 |
| CVSS 评分 | 9.4 |
| 严重程度 | 严重 |
| 发布时间 | 2026-06-28 |
| 状态 | Received |
数据来源: NVD | 获取时间: 2026-06-28 18:14
💬 评论