Known Vulnerabilities for Act Runner by Gitea
Listed below are 10 of the newest known vulnerabilities associated with "Act Runner" by "Gitea".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73232 json | ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory deni... | Not Provided | 2026-08-11 | 2026-08-12 |
| CVE-2026-72764 json | n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (befor... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-67426 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification ... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-61437 json | PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._r... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-58053 json | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job... | Not Provided | 2026-06-28 | 2026-06-30 |
| CVE-2026-57531 json | Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows un... | Not Provided | 2026-07-24 | 2026-07-25 |
| CVE-2026-57530 json | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/... | Not Provided | 2026-07-24 | 2026-07-25 |
| CVE-2026-56777 json | n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Cod... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-56776 json | n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new en... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-55576 json | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/releas... | Not Provided | 2026-07-15 | 2026-08-12 |