← All research

GHSA-846c-fpfg-rj9m

Arbitrary host filesystem & Docker-socket mounts via MCP server `mounts`

01Record

IdentifierGHSA-846c-fpfg-rj9m
Projectgh-aw
ComponentMCP server mounts (pkg/parser/mcp.go)
CVSS9.6
Disclosed2026-08-29
Endor referenceENDOR-VUL-2026-0906

02Detail

Description: Custom MCP server definitions in gh-aw accept a mounts: array that is copied, after a syntax-only check, into the container launch configuration of the compiled workflow. Validation enforces the shape source:destination:mode but does not restrict the host source path, so a malicious workflow component can mount the host filesystem root or /var/run/docker.sock into an MCP server container in the victim's CI. Affects versions up to 0.77.5; fixed in 0.86.2.

Impact: Container Escape, CI Runner Takeover. Mounting the Docker socket grants control of the Docker daemon, which is equivalent to root on the runner host. The input is authored in frontmatter and crosses the trust boundary of workflow components imported from third-party repositories.

Discovered by Peyton Kennedy (p80n).