ClawJacked Vulnerability in OpenClaw Could Let Websites Hijack AI Agents
ID: aa4cfe8b-70eb-5ce3-958f-50d3e665ef6a
STIX ID: report--aa4cfe8b-70eb-5ce3-958f-50d3e665ef6a
Feed Name: HackRead
Threat Score
**Executive summary:** Oasis Security disclosed 'ClawJacked' (CVE-2026-25253), a critical flaw in OpenClaw's gateway that trusted localhost WebSocket connections, enabling malicious webpages to brute-force local agent authentication at high speed, gain admin privileges, and exfiltrate sensitive data; OpenClaw issued a patch (2026.2.25+) within 24 hours and users must update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
