logo

OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration

ID: f6749d2b-5cd5-559a-9b39-2030d358a324

STIX ID: report--f6749d2b-5cd5-559a-9b39-2030d358a324

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CNCERT warned that OpenClaw — a popular open-source autonomous AI agent — has weak default security, privileged endpoint access, and is vulnerable to indirect prompt-injection (IDPI/XPIA) attacks that can leak sensitive data (including via link-preview exfiltration). Researchers and vendors have demonstrated practical exploitation paths, and threat actors have published malicious GitHub installers distributing info-stealers (Atomic, Vidar) and GhostSocks proxy malware; CNCERT and others recommend hardening deployments, isolating services, restricting management ports, and obtaining skills only from trusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.