Skip to content
devwallssecurity
Dense patch cabling running across the face of a rack
research / DW-2026-002

Container escape from a shared CI runner

The runner's default configuration mounted the host socket into build containers, allowing any repository with a pipeline to obtain root on the runner host and read other tenants' secrets.

affected
Self-hosted CI runner, default configuration
cvss v3.1
7.8
published
2026-05-09
status
Patched — configuration guidance updated
high
detail

This is not a subtle bug, and it is not new. It is on this list because we have now found it in eleven separate estates in two years, always in the same shape: a runner set up quickly for one trusted team, then opened to the wider organisation without revisiting the isolation model.

A pipeline in any repository could reach the host socket, start a privileged container, and read the secrets injected into every other pipeline on that runner. In three of the eleven cases this included production deployment credentials.

The fix is isolation per trust boundary rather than per team. We have published the runner configuration we recommend, along with a detection rule that fires on socket access from within a build container.

timeline
  1. 2026-01-20
    Pattern identified across multiple engagements
  2. 2026-03-11
    Coordinated notification to affected clients
  3. 2026-05-09
    Published with hardening guidance and detection rule
backall advisories
A dense city skyline at night, lit windows in red and amber

worried this affects you

If you run the affected product and are not sure whether you are exposed, send us the version and configuration. We will tell you, and there is no charge for that answer.