logo

Critical OpenClaw Vulnerability Exposes AI Agent Risks

ID: 662806d5-5409-5464-877b-028eb5ee4593

STIX ID: report--662806d5-5409-5464-877b-028eb5ee4593

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Jai Vijayan

...
...

Executive Summary: A high-severity vulnerability in the open-source OpenClaw AI agent could let attacker-controlled websites open WebSocket connections to the local gateway, brute-force weak authentication (no rate limits), and register malicious scripts to take control of a developer's device; the issue was patched in version 2026.2.25. The report also highlights multiple related CVEs, a rapidly growing ecosystem containing hundreds of malicious skills on ClawHub/SkillsMP, and documented use of those skills to distribute an Atomic macOS info stealer, indicating active malicious use and broad potential impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.