OpenClaw Vulnerability Exposes How an Open-Source AI Agent Can Be Hijacked
ID: 27019109-b16f-511b-9fa9-87bb8608bdce
STIX ID: report--27019109-b16f-511b-9fa9-87bb8608bdce
Feed Name: The Cyber Express
Researchers found a vulnerability chain in the OpenClaw agent whereby a malicious website's JavaScript can open a WebSocket to the locally bound gateway, brute-force or guess credentials because localhost attempts are exempt from rate limiting, gain administrative access, pair devices, and command the agent to exfiltrate data or execute arbitrary shell commands; OpenClaw issued a patch (2026.2.25) within 24 hours and the report urges immediate updates, credential audits, visibility into local AI tooling, and governance for agent identities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
