logo

From Clawdbot to Moltbot to OpenClaw: Security Experts Detail Critical Vulnerabilities and 6 Immediate Hardening Steps for the Viral AI Agent

ID: a4d97899-84b5-5104-b8b5-18b9df87db9f

STIX ID: report--a4d97899-84b5-5104-b8b5-18b9df87db9f

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Robert McSulla

...
...

**Moltbot (Clawdbot/OpenClaw) poses high agentic-AI security risks: researchers have identified multiple critical vulnerabilities (including RCE CVE-2026-25253, CVE-2026-24763, CVE-2026-25157), authentication bypasses behind reverse proxies, exposed web control interfaces, plaintext storage of API keys and conversation memories, and hundreds of malicious skills—creating clear paths to full system compromise, token/account takeover, and sensitive data/context exfiltration; the report enumerates these issues and prescribes immediate hardening steps (strict whitelisting, gateway/auth verification, sandboxing, audits, and token scoping).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.