OpenClaw 0-Click Flaw Lets Malicious Websites Hijack Developer AI Agents
ID: e1715431-8e76-525a-8703-6e0a54f46022
STIX ID: report--e1715431-8e76-525a-8703-6e0a54f46022
Feed Name: GBHackers
Threat Score
A critical 0‑click vulnerability in the OpenClaw local WebSocket gateway allowed attacker-controlled web pages to connect to localhost, brute-force gateway credentials (bypassing rate limits), register as trusted devices without user confirmation, and obtain full control of AI agents and connected devices—enabling credential theft, file exfiltration, Slack/API key harvesting, and remote command execution; OpenClaw patched the issue (version 2026.2.25+) within 24 hours.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
