logo

CVE-2025-32955: Security mechanism bypass in Harden-Runner Github Action

ID: 9857764a-29c8-5f62-aeca-c6b3e1bcabf7

STIX ID: report--9857764a-29c8-5f62-aeca-c6b3e1bcabf7

Feed Name: Sysdig Blog

Threat Score
60/100

Date Published: 2025-04-22

Date Updated: 2026-05-01

...
...

**CVE-2025-32955**: Sysdig TRT found a Harden-Runner vulnerability that allows an attacker with code execution inside a GitHub Actions job to bypass the action's disable-sudo control by using Docker (mounting host filesystem via a privileged container) to restore the runner sudoers file, enabling privilege escalation and disabling security controls; the issue is assigned CVSS v3.1 base score 6.0 and was fixed in Harden-Runner v2.12.0 released April 21, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.