Critical OpenClaw Vulnerability Exposes AI Agent Risks
ID: 662806d5-5409-5464-877b-028eb5ee4593
STIX ID: report--662806d5-5409-5464-877b-028eb5ee4593
Feed Name: Dark Reading
Executive Summary: A high-severity vulnerability in the open-source OpenClaw AI agent could let attacker-controlled websites open WebSocket connections to the local gateway, brute-force weak authentication (no rate limits), and register malicious scripts to take control of a developer's device; the issue was patched in version 2026.2.25. The report also highlights multiple related CVEs, a rapidly growing ecosystem containing hundreds of malicious skills on ClawHub/SkillsMP, and documented use of those skills to distribute an Atomic macOS info stealer, indicating active malicious use and broad potential impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
