logo

OpenClaw 0-Click Flaw Lets Malicious Websites Hijack Developer AI Agents

ID: e1715431-8e76-525a-8703-6e0a54f46022

STIX ID: report--e1715431-8e76-525a-8703-6e0a54f46022

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Divya

...
...

A critical 0‑click vulnerability in the OpenClaw local WebSocket gateway allowed attacker-controlled web pages to connect to localhost, brute-force gateway credentials (bypassing rate limits), register as trusted devices without user confirmation, and obtain full control of AI agents and connected devices—enabling credential theft, file exfiltration, Slack/API key harvesting, and remote command execution; OpenClaw patched the issue (version 2026.2.25+) within 24 hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.