GHSA-846c-fpfg-rj9m
Arbitrary host filesystem & Docker-socket mounts via MCP server `mounts`
01Record
| Identifier | GHSA-846c-fpfg-rj9m |
|---|---|
| Project | gh-aw |
| Component | MCP server mounts (pkg/parser/mcp.go) |
| CVSS | 9.6 |
| Disclosed | 2026-08-29 |
| Endor reference | ENDOR-VUL-2026-0906 |
02Detail
Description: Custom MCP server definitions in gh-aw accept a mounts: array that is copied, after a syntax-only check, into the container launch configuration of the compiled workflow. Validation enforces the shape source:destination:mode but does not restrict the host source path, so a malicious workflow component can mount the host filesystem root or /var/run/docker.sock into an MCP server container in the victim's CI. Affects versions up to 0.77.5; fixed in 0.86.2.
Impact: Container Escape, CI Runner Takeover. Mounting the Docker socket grants control of the Docker daemon, which is equivalent to root on the runner host. The input is authored in frontmatter and crosses the trust boundary of workflow components imported from third-party repositories.
Discovered by Peyton Kennedy (p80n).