PT-2026-6908 · Unknown · Harden-Runner

Devanshbatham

·

Published

2026-02-07

·

Updated

2026-02-28

·

CVE-2026-25598

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Harden-Runner versions prior to 2.14.2
Description Harden-Runner is a CI/CD security agent designed to function like an EDR for GitHub Actions runners. A security issue has been identified in the Community Tier of Harden-Runner that allows outbound network connections to bypass audit logging. Specifically, outbound traffic utilizing the sendto, sendmsg, and sendmmsg socket system calls can evade detection and logging when the egress-policy is set to 'audit'. This bypass requires an attacker to already have code execution capabilities within the GitHub Actions workflow. The issue does not affect the Enterprise Tier. The vulnerability stems from incomplete monitoring coverage of certain socket-related system calls, allowing attackers to establish covert communication channels using UDP traffic without generating audit events.
Recommendations Upgrade to Harden-Runner version 2.14.2 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25598
GHSA-CPMJ-H4F6-R6PQ

Affected Products

Harden-Runner