{"id":"GHSA-cpmj-h4f6-r6pq","summary":"Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)","details":"## Summary \n\nA security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the `sendto`, `sendmsg`, and `sendmmsg` socket system calls can bypass detection and logging when using `egress-policy: audit`. \n\n**Note:** This vulnerability only affects audit mode. When using `egress-policy: block`, these connections are properly blocked. It requires the attacker to already have code execution capabilities within the GitHub Actions workflow (e.g., through workflow injection or compromised dependencies)\n\n## Affected Versions \n\n- Harden-Runner Community Tier: All versions prior to v2.14.2 \n- Harden-Runner Enterprise Tier: **NOT AFFECTED** \n\n## Severity \n\n**Medium** - This vulnerability affects audit logging capabilities but requires the attacker to already have code execution within the workflow. \n\n## Impact \n\nWhen Harden-Runner is configured in audit mode (`egress-policy: audit`), attackers with the ability to execute arbitrary code in a workflow can: \n- Send outbound network traffic without generating audit logs \n- Bypass network monitoring for UDP-based communications \n\n**Important:** This vulnerability requires the attacker to already have code execution capabilities within the GitHub Actions workflow (e.g., through workflow injection or compromised dependencies). \n\n## Technical Details \n\nThe vulnerability stems from incomplete monitoring coverage of certain socket-related system calls. Specifically, the following system calls can be used to send UDP traffic without triggering audit events: \n\n- `sendto()` \n\n- `sendmsg()` \n\n- `sendmmsg()` \n\nAn attacker with code execution in a workflow can compile and execute native code that uses these system calls to establish covert communication channels. \n\n## Affected Users \n\n**This vulnerability ONLY affects users of the Harden-Runner Community Tier.** \n\nThe Harden-Runner Enterprise Tier is **NOT vulnerable** to this bypass technique. \n\n## Remediation \n\n### For Community Tier Users \n \n**Upgrade to Harden-Runner v2.14.2 or later.** This version includes fixes for the logging bypass vulnerability. \n\n### For Enterprise Tier Users \n\nNo action required. Enterprise tier customers are not affected by this vulnerability. \n\n## Credit \n\nWe would like to thank [Devansh Batham](https://github.com/devanshbatham) for responsibly disclosing this vulnerability through our security reporting process. Devansh was communicative throughout the process and verified the fix before the fix before it was made public.","aliases":["CVE-2026-25598"],"modified":"2026-09-15T06:34:20.077181866Z","published":"2026-02-09T17:19:14Z","database_specific":{"cwe_ids":["CWE-221","CWE-778","CWE-863"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-09T17:19:14Z","nvd_published_at":"2026-02-09T20:15:58Z"},"references":[{"type":"WEB","url":"https://github.com/step-security/harden-runner/security/advisories/GHSA-cpmj-h4f6-r6pq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25598"},{"type":"WEB","url":"https://github.com/step-security/harden-runner/commit/5ef0c079ce82195b2a36a210272d6b661572d83e"},{"type":"PACKAGE","url":"https://github.com/step-security/harden-runner"},{"type":"WEB","url":"https://github.com/step-security/harden-runner/releases/tag/v2.14.2"}],"affected":[{"package":{"name":"step-security/harden-runner","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.14.2"}]},{"type":"GIT","repo":"https://github.com/step-security/harden-runner","events":[{"introduced":"0"},{"fixed":"5ef0c079ce82195b2a36a210272d6b661572d83e"}]}],"versions":["v2.14.1","v2.14.0","v2.13.3","v2.13.2","v2.13.1","v2.13.0","v2.12.2","v2.12.1","v2.12.0","v2.11.1","v2.11.0","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.9.1","v2.9.0","v2.8.1","v2.8.0","v2.7.1","v2.7.0","v2.6.1","v2.6.0","v2.5.1","v2.5.0","v2.4.1","v2.4.0","v2.3.1","v2.3.0","v2.2.1","v2.2.0","v2.1.0","v2.0.0","v1.5.0","v1","v1.4.5","v1.4.4","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.0","v0.4.0","v0.3.0","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-cpmj-h4f6-r6pq/GHSA-cpmj-h4f6-r6pq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"}]}