CVE-2025-32955: Security mechanism bypass in Harden-Runner Github Action
ID: 9857764a-29c8-5f62-aeca-c6b3e1bcabf7
STIX ID: report--9857764a-29c8-5f62-aeca-c6b3e1bcabf7
Feed Name: Sysdig Blog
Threat Score
**CVE-2025-32955**: Sysdig TRT found a Harden-Runner vulnerability that allows an attacker with code execution inside a GitHub Actions job to bypass the action's disable-sudo control by using Docker (mounting host filesystem via a privileged container) to restore the runner sudoers file, enabling privilege escalation and disabling security controls; the issue is assigned CVSS v3.1 base score 6.0 and was fixed in Harden-Runner v2.12.0 released April 21, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
