Openclaw cli: OpenClaw: Docker container escape via unvalidated bind mount config injection (CVE-2026-27002)
Description
OpenClaw CLI versions up to 2026.2.14 contain a configuration injection vulnerability that allows dangerous Docker options to be applied in the sandbox environment. This can enable container escape or unauthorized access to host data by mounting sensitive host paths, using host networking, or disabling security profiles. The issue is fixed in version 2026.2.15 by blocking unsafe Docker settings and validating configuration schemas.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A configuration injection vulnerability in OpenClaw CLI's Docker sandbox allows attackers or misconfigured operators to inject dangerous Docker options such as bind mounts to sensitive host directories, host networking, and unconfined seccomp or AppArmor profiles. These options can lead to container escape or host compromise by exposing the Docker socket or sensitive host files. The vulnerability affects versions >=2026.1.29 and <2026.2.15. The fix, introduced in version 2026.2.15, enforces runtime checks on Docker create arguments, validates configuration schemas to disallow unsafe settings, and includes security audit enhancements.
Potential Impact
If exploited, this vulnerability can allow an attacker to mount critical host directories (e.g., /etc, /proc, /sys, /dev, Docker socket), bypass container network isolation using host networking, and disable container security profiles. This can result in exfiltration of host secrets or full host control via Docker socket exposure.
Mitigation Recommendations
A fix is available in OpenClaw CLI version 2026.2.15 and later, which blocks dangerous Docker sandbox settings and validates configuration schemas. Until upgrading, avoid configuring sandbox Docker bind mounts to system directories or Docker socket paths, keep Docker network settings at 'none' or 'bridge', and do not use 'unconfined' for seccomp or AppArmor profiles.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-27002
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac245ce12601ec6a3167fd7
Added to database: 10/04/2026, 12:25:50 UTC
Last enriched: 10/04/2026, 13:13:17 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.