Executive brief
OpenClaw is an open-source application with Docker containers used for testing and deployment. Multiple test and end-to-end testing Dockerfiles run all processes with root privileges (uid 0), which means if any service inside the container is compromised, an attacker gains full root access and can more easily break out of the container or access sensitive data on the host system. This risk is heightened because test images share the same base configuration as production images, raising the possibility of accidentally deploying insecure root-level containers to production.
Technical details
The vulnerability is a privilege escalation issue (CWE-250: Execution with Unnecessary Privileges) in four Dockerfiles that lack a USER directive. Affected files are scripts/e2e/Dockerfile, scripts/e2e/Dockerfile.qr-import, scripts/docker/install-sh-e2e/Dockerfile, and scripts/docker/install-sh-nonroot/Dockerfile. Without an explicit USER directive, Docker containers default to running all processes as uid 0 (root). An attacker who compromises any process inside these containers gains root access, enabling kernel exploit attempts, volume mount abuse, and privileged syscall execution. A partial fix was applied in commit 28e1a65e which added USER directives to Dockerfile.sandbox and Dockerfile.sandbox-browser, but the E2E/test images remain unpatched. The fix requires adding a USER directive (e.g., `RUN useradd --create-home --shell /bin/bash appuser` followed by `USER appuser`) before the CMD/ENTRYPOINT in each Dockerfile. The vendor has released patched versions >= 2026.2.21.
Affected products
- OpenClaw OpenClaw <= 2026.2.19-2
Timeline
- 2026-02-21: disclosed
- 2026-02-21: patched: Fixed in version 2026.2.21