logo

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

ID: 17f4d328-69df-5d3c-a22f-a3e5a4d9b52c

STIX ID: report--17f4d328-69df-5d3c-a22f-a3e5a4d9b52c

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-10

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

The report details three now-patched high-severity vulnerabilities in the OpenClaw AI assistant (GHSA-hjr6-g723-hmfm, GHSA-9969-8g9h-rxwm, GHSA-575v-8hfq-m3mc) — two OS command-injection issues and a path-traversal/link-following flaw — that can be abused to read SSH/AWS/GPG secrets, achieve arbitrary host code execution, and escape sandboxes (e.g., via mounting parent directories or accessing the Docker socket). The researcher demonstrated a plausible remote trigger (external messages such as WhatsApp); OpenClaw maintainers released version 2026.6.6 and recommend upgrading plus sandboxing and stricter allowlists as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.