### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces a
Ubuntu Linux | Docker
Vulnerability
CVE-2026-73802
GHSA
Refer to CVE-2026-73802 NVD advisory