Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

CVE-2025-32955: Security mechanism bypass in Harden-Runner Github Action

Blog post from Sysdig

Post Details
Company
Date Published
Author
Lorenzo Susini
Word Count
1,373
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

CVE-2025-32955 is a vulnerability discovered in the Harden-Runner GitHub Action, a widely used security tool in CI/CD environments, which allowed attackers to bypass its disable-sudo security mechanism, thus enabling them to execute code with elevated privileges undetected. This vulnerability, now patched in version v2.12.0, was found by the Sysdig Threat Research Team and involved exploiting the Linux runner user account's membership in the Docker group, which allowed the execution of privileged operations by restoring the sudoers file. As a result, attackers could disrupt security mechanisms and compromise the integrity and availability of Harden-Runner's protections. Users are advised to update to the latest version to mitigate this risk, as the vulnerability underscores the growing threat of supply chain attacks in modern security frameworks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 1,622 159 73 +32%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.