logo

China’s CERT warns OpenClaw can inflict nasty wounds

ID: de1468fa-ddaa-59f0-a26c-810cdb4f4054

STIX ID: report--de1468fa-ddaa-59f0-a26c-810cdb4f4054

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-03-12

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

China’s national CERT warned that the agentic AI tool OpenClaw has weak default security, multiple disclosed severe vulnerabilities (including ones that could enable credential theft), and is susceptible to attacks via malicious web instructions and poisoned plugins. The advisory recommends isolating OpenClaw in containers or nonproduction VMs, restricting management ports and plugin access, enforcing strict authentication, and disabling automatic updates; the tool’s rapid uptake and one-click cloud deployments prompted some government bans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.