CVE-2026-25598Disclosure(stepsecurity / harden-runner)

MEDIUMCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch stepsecurity harden-runner systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto, sendmsg, and sendmmsg socket system calls can bypass detection and logging when using egress-policy: audit. This vulnerability is fixed in 2.14.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-778

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • harden-runner

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-09); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Products
harden-runner

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-07: 1Mentions · 2026-02-09: 3Mentions · 2026-02-11: 2PoC Mentioned / Linked · 2026-02-11: 1Exploit Tool / Code · 2026-02-11: 1Patch / Workaround · 2026-02-07: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-11: 102-0702-0902-11
Signal classification4 categories
Disclosure
233.3%
General
233.3%
Patch
116.7%
Exploit
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-071
Patch1
2026-02-093
Disclosure2General1
2026-02-112
Exploit1General1
Full discourse6 posts
  • Devansh (⚡, 🥷)@0xAsm0d3us
    General

    New Write-up! [CVE-2026-25598] Bypassing Outbound Connections Detection in harden-runner https://devansh.bearblog.dev/harden-runner/ https://t.co/2JAon9wi8f

    Post summary

    The tweet links to a write‑up on CVE‑2026‑25598 but provides no concrete details about the vulnerability, PoC, exploit code, patches, or active exploitation.

    111053243.1K
    16.1K followersView on X
  • Devansh (⚡, 🥷)@0xAsm0d3us
    Patch

    Recently reported an issue related to evasion of logging of outbound networks connections in harden-runner GitHub action using connectionless UDP syscalls (sendto, sendmsg, and sendmmg), this is now fixed and disclosed. CVE-2026-25598 https://github.com/step-security/harden-runner/security/advisories/GHSA-cpmj-h4f6-r6pq https://t.co/k7ZxpdNffj

    Post summary

    A recently disclosed vulnerability (CVE-2026-25598) in the harden-runner GitHub action that bypasses logging of outbound UDP connections has been fixed and patched.

    0303652.5K
    16.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25598 Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden… https://www.cve.org/CVERecord?id=CVE-2026-25598

    Post summary

    The text announces the existence of CVE-2026-25598 in Harden-Runner before version 2.14.2, but provides no further technical details or mitigation information.

    00010154
    56.5K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Exploit

    🚨 #CVE-2026-25598 Exposed: How Attackers Bypass Outbound Connection Detection in #GitHub’s Harden-Runner – Full Exploit Guide https://undercodetesting.com/cve-2026-25598-exposed-how-attackers-bypass-outbound-connection-detection-in-githubs-harden-runner-full-exploit-guide/ Educational Purposes!

    Post summary

    The post announces a detailed exploit guide for CVE‑2026‑25598, outlining how attackers bypass outbound connection detection in GitHub’s Harden‑Runner, but does not mention active attacks or available patches.

    0000037
    393 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25598 Audit Bypass in Harden-Runner GitHub Action Community Tier via Socket System Calls https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25598

    Post summary

    The text announces CVE-2026-25598, an audit bypass vulnerability in Harden-Runner GitHub Action involving socket system calls, without providing a PoC, exploit, or patch details.

    0000053
    4.0K followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-25598: The Invisible Courier: Bypassing Harden-Runner's Watchful Eye via Syscall Ninja Tactics In the world of CI/CD security, visibility is everything. Step Security's Harden-Runner promises to be the all-seeing eye for GitHub Actions, monit... https://cvereports.com/reports/CVE-2026-25598

    Post summary

    The excerpt announces a CVE with a headline but offers no substantive details, proof‑of‑concept, exploit information, or patch guidance.

    00000106
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstepsecurityharden-runner---

Explore more