Executive brief
OpenClaw is an AI automation platform that uses containerized browsers to perform actions on websites and systems. The platform was launching these browsers with the Chrome --no-sandbox flag enabled by default, which disabled critical OS-level security protections that prevent compromised browser processes from accessing the host system. An attacker exploiting a browser rendering vulnerability could bypass the sandbox entirely and gain direct access to the container environment, significantly increasing the blast radius of any browser-based attack.
Technical details
This vulnerability is a protection mechanism failure (CWE-693) in OpenClaw's sandbox browser container entrypoint. By default, the container was launched with Chromium's --no-sandbox flag, which disables the OS-level sandbox that normally isolates the renderer process. This means a renderer-side vulnerability (e.g., in WebKit or V8 parsing) could be exploited without requiring a separate sandbox escape exploit—the attacker gains immediate access to the container's file system and resources. The attack requires local/container-level code execution and assumes the browser processes user-controlled content. The fix removes --no-sandbox from the default configuration and provides explicit opt-in via environment variables (OPENCLAW_BROWSER_NO_SANDBOX / CLAWDBOT_BROWSER_NO_SANDBOX), along with container hash migration and security audit checks to detect stale configurations.
Affected products
- OpenClaw openclaw <= 2026.2.19-2
Timeline
- 2026-03-03: disclosed: GHSA-43x4-g22p-3hrq published on GitHub Security Advisory
- 2026-02-21: patched: Fix commits e7eba01 and 1835dec authored; patched version 2026.2.21 planned for next release
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-43x4-g22p-3hrq
- https://github.com/openclaw/openclaw/commit/1835dec2004fe7a62c6a7ba46b8485f124ec6199
- https://github.com/openclaw/openclaw/commit/e7eba01efc4c3c400e9cfd3ce3d661cbc788a631
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-os-level-sandbox-bypass-via-no-sandbox-flag