Executive brief
OpenClaw is a sandbox browser container that uses Chromium to safely isolate untrusted web content. Versions prior to 2026.2.21 disabled Chromium's OS-level sandbox protections by default, allowing attackers who compromise the browser renderer to execute arbitrary code on the host system without needing to exploit additional sandbox escape vulnerabilities. This significantly increases the impact of browser-based attacks and weakens the isolation that organizations rely on to safely browse untrusted content.
Technical details
The vulnerability is rooted in improper sandbox configuration (CWE-693) where the OpenClaw sandbox browser container launched Chromium with the --no-sandbox flag by default, disabling OS-level sandbox protections. An attacker exploiting a renderer-side vulnerability in Chromium can achieve arbitrary code execution on the host system without requiring a separate sandbox escape, since the sandbox was already disabled at startup. The attack vector is local with low privilege requirements—a user must interact with untrusted content in the sandboxed browser. The fix removes the --no-sandbox flag from the default configuration and requires explicit opt-in via environment variables (OPENCLAW_BROWSER_NO_SANDBOX / CLAWDBOT_BROWSER_NO_SANDBOX) for users who need this behavior. Patches are available in version 2026.2.21 and later.
Affected products
- OpenClaw OpenClaw <2026.2.21
Timeline
- 2026-02-21: disclosed
- 2026-02-21: patched: Version 2026.2.21 released with fix
- 2026-03-21: advisory: GHSA-q94v-v6m9-jhq9 published
- 2026-03-24: other: Advisory withdrawn as duplicate of GHSA-43x4-g22p-3hrq