CVE-2025-32955

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Apr 21, 2025
Updated: Apr 23, 2025
CWE ID 268
CWE ID 269

Summary

CVE-2025-32955 is a vulnerability affecting versions 0.12.0 to before 2.12.0 of Harden-Runner, a CI/CD security agent for GitHub Actions runners. Despite the presence of a `disable-sudo` policy option intended to prevent the use of sudo, the runner user, which is also a member of the docker group, can bypass this restriction by interacting with the Docker daemon. This allows the attacker to launch privileged containers or access the host filesystem, effectively bypassing the sudo restriction and regaining root access or restoring the sudoers file. This issue has been resolved in version 2.12.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Harden-Runner

Affected Vendors

  • StepSecurity