T06 · System Persistence
- Location
scripts/install.py:57- Finding
Persistent Docker Container Automatically Restarts Across Sessions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install.py:57-63
Vulnerability Type: Persistent system service
Risk Level: MediumVulnerable Code
python run( "docker run -d --name searxng-local " "-p 127.0.0.1:8080:8080 " f"-v {SETTINGS_FILE}:/etc/searxng/settings.yml " "--restart unless-stopped " "searxng/searxng" )The persistence is also disclosed in
SKILL.md:49-55:markdown ⚠ Installation deploys a persistent Docker container (`searxng-local`) with `--restart unless-stopped`. To remove it:docker rm -f searxng-local
text Technical Analysis
The installer assigns the Docker restart policy
unless-stopped. Docker records this policy and automatically starts the container again when the Docker daemon or host restarts unless an administrator explicitly stops or removes it.Although the behavior is documented, it causes code from the selected container image to execute beyond the lifetime of the installation process and across subsequent sessions. This represents system persistence. The risk is amplified by the use of an unpinned container image because the persistent component is not tied to an immutable, audited digest.
The service port is restricted to
127.0.0.1, which reduces remote network exposure but does not eliminate the persistence or supply-chain risk.Attack Path
- A user runs
python scripts/install.py. - The installer creates the
searxng-localcontainer with--restart unless-stopped. - Docker stores the restart policy.
- After the Docker daemon or host restarts, Docker automatically executes the container again.
- Any malicious or subsequently compromised code present in the container image gains recurring execution under the Docker-managed container context.
Impact Assessment
The container receives persistent execution within its Docker isolation boundary. It has ...[truncated 267 chars]
- A user runs
- Remediation
View remediation
Remediation Suggestions
- Remove
--restart unless-stoppedfrom the default installation. - If persistent operation is required, make it an explicit opt-in option and clearly explain its lifecycle and security implications before installation.
- Use a nonpersistent default such as
--restart no. - Pin the container to a reviewed version and immutable SHA-256 digest.
- Provide and document an uninstall command that removes the container, associated restart policy, generated configuration, and any related resources.
- Consider running the service with additional Docker hardening, including a read-only filesystem, dropped Linux capabilities, resource limits, and a non-root user where supported.
- Remove
