ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
ID: dee3504e-0cf5-5924-aaf0-fb3fd30aa7a8
STIX ID: report--dee3504e-0cf5-5924-aaf0-fb3fd30aa7a8
Feed Name: The Hacker News
OpenClaw fixed a high-severity 'ClawJacked' vulnerability that allowed attacker-controlled websites to open WebSocket connections to a local OpenClaw gateway, brute-force its password, auto-register as a trusted device, and fully control the AI agent; additional issues include log poisoning and multiple CVEs enabling RCE/SSRF/authentication bypass, while malicious skills on the ClawHub marketplace have been used to distribute Atomic Stealer (notably via IP 91.92.242.30) in active supply-chain campaigns—users are urged to update, audit skills, and isolate runtimes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
