ClawJacked Bug Enables Covert AI Agent Hijacking
ID: 05e07a76-aeb6-5104-a1c0-a9cab9cd4dd6
STIX ID: report--05e07a76-aeb6-5104-a1c0-a9cab9cd4dd6
Feed Name: Infosecurity Magazine (News)
Threat Score
Researchers disclosed a high-severity vulnerability in OpenClaw ("ClawJacked") where a local gateway bound to localhost can be abused by a malicious webpage to open a WebSocket to the gateway, brute-force the password (localhost is exempt from rate limiting), auto-pair as a trusted device, and achieve full remote control of the OpenClaw instance and connected nodes; users are urged to update to version 2026.2.25+ and implement governance and access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
