ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

A high-severity security flaw that may have allowed a malicious website to connect to a locally running artificial intelligence (AI) agent and seize control if it had been successfully exploited has been addressed by OpenClaw.

According to a report released this week by Oasis Security, Our vulnerability lives in the core system itself—no plugins, no marketplace, no user-installed extensions, just the bare OpenClaw gateway, running exactly as documented.

The cybersecurity firm has given the vulnerability the nickname ClawJacked.

The following threat model is assumed by the attack: On a developer’s laptop, OpenClaw is configured and operational. Its gateway, a local WebSocket server, is password-protected and linked to localhost. When the developer visits a website under the attacker’s control via social engineering or another method, the attack begins read more about ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *