logo

ClawJacked attack let malicious websites hijack OpenClaw to steal data

ID: 493f5d40-dc1d-539a-bd31-d55893a6291e

STIX ID: report--493f5d40-dc1d-539a-bd31-d55893a6291e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-01

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Security researchers disclosed "ClawJacked," a high-severity vulnerability in the self-hosted AI platform OpenClaw that allowed browser JavaScript to open WebSocket connections to a localhost gateway, brute-force the management password at hundreds of attempts per second, and auto-register as a trusted device—potentially enabling credential theft, file exfiltration, arbitrary command execution, and full workstation compromise; OpenClaw released a fix in version 2026.2.26 and administrators should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.