OpenClaw patches one-click RCE as security Whac-A-Mole continues
ID: f0e19909-eba4-5d78-9e1c-53441a96c348
STIX ID: report--f0e19909-eba4-5d78-9e1c-53441a96c348
Feed Name: The Register (Security)
Threat Score
Security researchers disclosed a one-click RCE in the OpenClaw AI project that leverages missing WebSocket origin validation to steal authentication tokens and execute commands on vulnerable servers; the project published an advisory and patched the flaw. Separately, Moltbook had its database and secret API keys exposed, potentially allowing attackers to post as any registered agent, and that issue was reported and fixed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
