
A severe vulnerability was disclosed for Gitea act_runner (CVE-2026-58053) https://vuldb.com/vuln/374503
Post summary
The short announcement simply reveals the existence of CVE-2026-58053 and provides a link to a vulnerability database entry.
Signal is active with 4 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE

A severe vulnerability was disclosed for Gitea act_runner (CVE-2026-58053) https://vuldb.com/vuln/374503
Post summary
The short announcement simply reveals the existence of CVE-2026-58053 and provides a link to a vulnerability database entry.

CVE-2026-58053 Container Escape to Root in Gitea act_runner Docker Backend via U... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58053 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4
Post summary
The post merely references CVE-2026-58053 with a brief mention of a container‑escape vulnerability, providing no PoC, exploit code, patch information, or evidence of active exploitation.

🚨 CVE-2026-58053 — CVSS 9.9/10 ██████████ Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/IZ1fBPE1iN
Post summary
CVE‑2026‑58053 is a critical flaw in Gitea’s act_runner Docker backend; a patch is available immediately.

CVE-2026-58053 (CVSS 9.9) affects Gitea act_runner Docker backend. Organizations using self-hosted runners should review the advisory. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/fvDg2ALVzR
Post summary
The tweet discloses a high‑severity CVE affecting Gitea’s act_runner Docker backend and recommends reviewing the advisory.