logo

ClawJacked Bug Enables Covert AI Agent Hijacking

ID: 05e07a76-aeb6-5104-a1c0-a9cab9cd4dd6

STIX ID: report--05e07a76-aeb6-5104-a1c0-a9cab9cd4dd6

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

...
...

Researchers disclosed a high-severity vulnerability in OpenClaw ("ClawJacked") where a local gateway bound to localhost can be abused by a malicious webpage to open a WebSocket to the gateway, brute-force the password (localhost is exempt from rate limiting), auto-pair as a trusted device, and achieve full remote control of the OpenClaw instance and connected nodes; users are urged to update to version 2026.2.25+ and implement governance and access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.