logo

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

ID: 4ad4f1b7-c0fe-5ad1-ae27-13525edecb01

STIX ID: report--4ad4f1b7-c0fe-5ad1-ae27-13525edecb01

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

Author: [email protected] (The Hacker News)

...
...

OpenClaw, a self-hosted AI agent, was found by Imperva and Varonis to be susceptible to prompt-injection and agent-phishing: hidden instructions embedded in shared contacts/vCards/location labels (flattened into the LLM prompt) can induce execution of attacker-controlled code, and believable emails can trick agents into forwarding credentials and datasets. Imperva fixed the message-object handling in release 2026.4.23 and other connector allowlist issues were patched, but the architectural risk — agents that read private data, accept untrusted content, and can send data out — remains and requires guardrails (outbound mail gates, connector trust tracking, human approval for high-risk actions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.