ClawJacked attack let malicious websites hijack OpenClaw to steal data
ID: 493f5d40-dc1d-539a-bd31-d55893a6291e
STIX ID: report--493f5d40-dc1d-539a-bd31-d55893a6291e
Feed Name: Bleeping Computer
Security researchers disclosed "ClawJacked," a high-severity vulnerability in the self-hosted AI platform OpenClaw that allowed browser JavaScript to open WebSocket connections to a localhost gateway, brute-force the management password at hundreds of attempts per second, and auto-register as a trusted device—potentially enabling credential theft, file exfiltration, arbitrary command execution, and full workstation compromise; OpenClaw released a fix in version 2026.2.26 and administrators should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
