Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
ID: 17f4d328-69df-5d3c-a22f-a3e5a4d9b52c
STIX ID: report--17f4d328-69df-5d3c-a22f-a3e5a4d9b52c
Feed Name: The Hacker News
The report details three now-patched high-severity vulnerabilities in the OpenClaw AI assistant (GHSA-hjr6-g723-hmfm, GHSA-9969-8g9h-rxwm, GHSA-575v-8hfq-m3mc) — two OS command-injection issues and a path-traversal/link-following flaw — that can be abused to read SSH/AWS/GPG secrets, achieve arbitrary host code execution, and escape sandboxes (e.g., via mounting parent directories or accessing the Docker socket). The researcher demonstrated a plausible remote trigger (external messages such as WhatsApp); OpenClaw maintainers released version 2026.6.6 and recommend upgrading plus sandboxing and stricter allowlists as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
