T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Unauthenticated Chrome DevTools Protocol Exposed on All Host Interfaces
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 18
Vulnerability Type: Unrestricted network exposure of a privileged browser-control interface
Risk Level: HighVulnerable Code
bash docker run -d --name browser-auto -p 9222:9222 --shm-size=512m chromedp/headless-shell:latestTechnical Analysis
Docker's
-p 9222:9222syntax publishes container port 9222 on all host interfaces by default. The Chrome DevTools Protocol (CDP) endpoint provides extensive control over the browser, while this deployment adds neither authentication nor a network access restriction.The later use of
http://127.0.0.1:9222for verification and OpenClaw configuration does not restrict the Docker port binding. Therefore, the service may remain reachable through other host interfaces unless an external firewall independently blocks it.An attacker with network access to TCP port 9222 can enumerate debugging targets, obtain a DevTools WebSocket endpoint, attach to browser contexts, execute JavaScript, inspect pages, and manipulate browser sessions.
Attack Path
- A user runs the documented Docker command.
- Docker publishes port 9222 on every host interface.
- An attacker reaches the host over a local, cloud, or otherwise permitted network path.
- The attacker requests CDP discovery endpoints such as
/json/versionor/json. - The endpoint returns a DevTools WebSocket URL.
- The attacker connects to that WebSocket and issues CDP commands.
- The attacker controls browser tabs, reads browser-visible data, executes JavaScript, and performs actions within active web sessions.
Impact Assessment
Successful exploitation grants remote control over the headless browser and its active browsing contexts. Depending on browser usage, this can expose page content, authentication state, session-bound application data, and actions available to logged-in users. The attacker may also use browser network acc ...[truncated 299 chars]
- Remediation
View remediation
Remediation Suggestions
Bind the CDP port exclusively to loopback when OpenClaw runs on the same host:
bash docker run -d \ --name browser-auto \ -p 127.0.0.1:9222:9222 \ --shm-size=512m \ chromedp/headless-shell@sha256:<verified-digest>Additionally:
- Do not expose CDP directly to public or untrusted networks.
- For remote connectivity, use an authenticated VPN or SSH tunnel.
- If a reverse proxy is necessary, require strong authentication and TLS.
- Apply host and cloud firewall rules that permit only specifically authorized sources.
- Run the container with least privilege, a read-only filesystem where practical, dropped Linux capabilities, and appropriate resource limits.
- Verify exposure after deployment using interface and firewall inspection rather than relying only on the configured client URL.
