Executive brief
OpenClaw's sandbox browser component exposes the Chrome DevTools Protocol (CDP) via a relay service that could be accessed by peer containers on the same Docker network without authentication. The CDP protocol provides complete browser control, allowing attackers to execute arbitrary JavaScript, steal cookies, or hijack navigation. This vulnerability affects deployments where OpenClaw containers run alongside untrusted or compromised peer containers on shared Docker networks.
Technical details
The vulnerability exists in the sandbox browser CDP relay (socat) configuration, which bound to 0.0.0.0 inside the container without enforcing source-range restrictions by default. While host-side binding was already restricted to 127.0.0.1, peer containers on the same Docker bridge network could reach the relay unauthenticated. The root cause is that the CDP_SOURCE_RANGE environment variable was optional and defaulted to empty. The fix enforces mandatory source-range restriction by auto-deriving it from the Docker network gateway IP and refusing to start the socat relay without one. For bridge-style networks, the gateway IP is automatically detected; for non-bridge drivers (macvlan, ipvlan, overlay), explicit configuration is required. The patch is available in openclaw 2026.4.10 and later.
Affected products
- OpenClaw openclaw < 2026.4.10
Timeline
- 2026-04-17: disclosed
- 2026-04-10: patched: Fix merged in PR #61404; first stable release v2026.4.10