Container Hardening Bypass in Gitea act_runner Docker Backend
CVE-2026-58053 is a critical container hardening bypass affecting Gitea act_runner when using the Docker backend through act 0.262.0. The flaw arises because a workflow's container.options string is merged into the Docker job container HostConfig. When the runner is configured with privileged: false, it only forces the Docker Privileged flag to false, but does not sanitize or strip other dangerous Docker options. As a result, workflow-supplied flags such as --pid=host, --cap-add, and --security-opt are preserved and applied to the job container. An attacker with the ability to run a workflow on a Docker-backed runner can abuse these options to create a container with host namespaces and expanded capabilities, enabling escape from the containerized job environment to the underlying host as root despite privileged mode being disabled.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.