{"id":"GHSA-ww6v-v748-x7g9","summary":"OpenClaw has a sandbox network isolation bypass via docker.network=container:\u003cid\u003e","details":"### Summary\nIn `openclaw@2026.2.23`, sandbox network hardening blocks `network=host` but still allows `network=container:\u003cid\u003e`.\n\nThis can let a sandbox join another container's network namespace and reach services available in that namespace.\n\n### Preconditions and Trust Model Context\nThis issue requires a trusted-operator configuration path (for example setting `agents.defaults.sandbox.docker.network` in gateway config). It is not an unauthenticated remote exploit by itself.\n\n### Details\nCurrent validation blocks only `host`, while forwarding other values to Docker create args:\n\n- `validateNetworkMode(network)` only rejects values in `BLOCKED_NETWORK_MODES = {\"host\"}`.\n- `buildSandboxCreateArgs(...)` validates then forwards `cfg.network` into `--network`.\n- Browser sandbox helper also treats `container:` as an accepted mode in network preparation.\n\nEffective behavior:\n\n- `host` -\u003e blocked\n- `container:\u003cid\u003e` -\u003e accepted and forwarded\n\n### Impact\nType: sandbox network isolation hardening bypass.\n\nPractical impact depends on deployment:\n\n- Requires ability to influence trusted sandbox network config.\n- Higher impact when a target container exposes privileged/internal network reachability.\n\n### Remediation\nBlock namespace-join style network modes (including `container:\u003cid\u003e`) for sandbox containers, and keep strict allowlisting for safe network modes.\n\n\n### Patch Status\nFixed on `main` in commit `14b6eea6e`:\nhttps://github.com/openclaw/openclaw/commit/14b6eea6e\n\nFollow-up refactor/cleanup (no policy rollback):\nhttps://github.com/openclaw/openclaw/commit/5552f9073\n\n\n### Publication Update (2026-02-25)\n`openclaw@2026.2.24` is published on npm and contains the fix commit(s) listed above. This advisory now marks `\u003e= 2026.2.24` as patched.","aliases":["CVE-2026-32038"],"modified":"2026-03-25T20:41:22.603091Z","published":"2026-03-02T23:37:46Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-03-02T23:37:46Z","nvd_published_at":"2026-03-19T22:16:39Z","cwe_ids":["CWE-284","CWE-693"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-ww6v-v748-x7g9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32038"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/14b6eea6e"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/5552f9073"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/openclaw-sandbox-network-isolation-bypass-via-docker-network-container-parameter"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.2.24"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2026.2.23","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-ww6v-v748-x7g9/GHSA-ww6v-v748-x7g9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}