New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
ID: 4ad4f1b7-c0fe-5ad1-ae27-13525edecb01
STIX ID: report--4ad4f1b7-c0fe-5ad1-ae27-13525edecb01
Feed Name: The Hacker News
OpenClaw, a self-hosted AI agent, was found by Imperva and Varonis to be susceptible to prompt-injection and agent-phishing: hidden instructions embedded in shared contacts/vCards/location labels (flattened into the LLM prompt) can induce execution of attacker-controlled code, and believable emails can trick agents into forwarding credentials and datasets. Imperva fixed the message-object handling in release 2026.4.23 and other connector allowlist issues were patched, but the architectural risk — agents that read private data, accept untrusted content, and can send data out — remains and requires guardrails (outbound mail gates, connector trust tracking, human approval for high-risk actions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
