logo

OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks

ID: 9b3038fd-3f1a-5ae7-b142-cd76c3928275

STIX ID: report--9b3038fd-3f1a-5ae7-b142-cd76c3928275

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-04-21

Author: Abinaya

...
...

This report explains how OpenClaw AI agents with insecure defaults can be abused via indirect prompt injection to create attacker-controlled URLs containing sensitive data; messaging platforms' auto-preview features then silently fetch those URLs, enabling 0-click exfiltration. The write-up cites PromptArmor and CNCERT demonstrations, outlines affected areas (messaging integrations, host/container access, unvetted skills, proximity to secrets), and recommends mitigations such as disabling auto-previews, isolating runtimes, restricting filesystem access, vetting skills, and monitoring agent-generated links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.