logo

ClawJacked flaw exposed OpenClaw users to data theft

ID: 23b91fb6-9e94-5be6-8340-167641f7c2a0

STIX ID: report--23b91fb6-9e94-5be6-8340-167641f7c2a0

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**ClawJacked**: A high-severity flaw in the OpenClaw local AI agent framework let malicious websites open WebSocket connections to a localhost gateway, brute-force its password (rate limiting exempted for localhost), silently register as a trusted device, and gain admin-level control to exfiltrate data or execute commands; Oasis Security disclosed the issue and OpenClaw issued a patch (version 2026.2.26) — update immediately and audit agent permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.