logo

ClawJacked Vulnerability in OpenClaw Could Let Websites Hijack AI Agents

ID: aa4cfe8b-70eb-5ce3-958f-50d3e665ef6a

STIX ID: report--aa4cfe8b-70eb-5ce3-958f-50d3e665ef6a

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** Oasis Security disclosed 'ClawJacked' (CVE-2026-25253), a critical flaw in OpenClaw's gateway that trusted localhost WebSocket connections, enabling malicious webpages to brute-force local agent authentication at high speed, gain admin privileges, and exfiltrate sensitive data; OpenClaw issued a patch (2026.2.25+) within 24 hours and users must update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.