CNCERT Warns OpenClaw Security Risks
💡Urgent OpenClaw risks exposed—secure deployments before breaches hit AI apps.
⚡ 30-Second TL;DR
What Changed
Improper OpenClaw installs caused serious security risks.
Why It Matters
Exposes vulnerabilities in AI agent deployments, potentially leading to exploits; practitioners must harden setups to maintain trust and avoid breaches in production environments.
What To Do Next
Audit your OpenClaw instance today: isolate ports with firewalls and containerize to limit privileges.
Key Points
- •Improper OpenClaw installs caused serious security risks.
- •Isolate management port; use auth, containers to limit privileges.
- •Avoid plaintext keys in env vars; enable full audit logs.
- •Use only signed plugins from trusted sources; disable auto-updates.
- •Apply security patches and monitor updates promptly.
🧠 Deep Insight
Background and context from public sources — not the original article. 7 sources cited.
🔑 Enhanced Key Takeaways
- •CVE-2026-25253 (CVSS 8.8) enables one-click remote code execution through WebSocket authentication token exfiltration, affecting all OpenClaw versions before 2026.1.29, with over 42,665 publicly exposed instances identified as of late January 2026[2].
- •The ClawHub marketplace contains approximately 800+ malicious skills (~20% of the registry) primarily delivering Atomic macOS Stealer (AMOS) and credential-harvesting payloads, with infostealers like RedLine, Lumma, and Vidar actively targeting OpenClaw configuration files[1][2].
- •OpenClaw's default configuration ships with authentication disabled and stores credentials in plaintext config files, creating a dual-layer vulnerability that enables both unauthorized access and credential compromise at scale[1].
- •Permission misconfiguration risks stem from OpenClaw's autonomous skill-chaining architecture, where a single overprivileged skill can escalate into lateral movement across systems, particularly when deployed with root access and open APIs[5].
🛠️ Technical Deep Dive
Cve_2026_25253_attack_chain
- •Stage 1: Attacker creates malicious webpage containing JavaScript payload
- •Stage 2: Cross-Site WebSocket Hijacking (CSWSH) exploits missing Origin header validation on OpenClaw's WebSocket server (e.g., ws://localhost:18789)
- •Stage 3: Victim's browser becomes bridge into local network; gateway authentication token exfiltrated
- •Stage 4: Attacker gains full administrative control in milliseconds with no prior access required[2]
Exposure_metrics
- •Censys tracked growth from ~1,000 to 21,000+ publicly exposed instances between January 25-31, 2026[2]
- •Bitsight observed 30,000+ instances across broader analysis window[2]
- •Independent researcher Maor Dayan identified 42,665 exposed instances with 5,194 actively verified as vulnerable; 93.4% exhibited authentication bypass conditions[2]
Credential_storage_vulnerabilities
Skill_marketplace_compromise
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
📎 Sources (7)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- pacgenesis.com — Openclaw Security Risks What Security Teams Need to Know About AI Agents Like Openclaw in 2026
- conscia.com — The Openclaw Security Crisis
- runzero.com — Openclaw
- fortune.com — Openclaw AI Agents Security Risks Beware
- security.com — Rise Openclaw
- mastercard.com — Openclaw AI Security Standards
- darkreading.com — Critical Openclaw Vulnerability AI Agent Risks
📰 Event Coverage
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: 36氪 ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
Weekly AI briefing
One email a week. Unsubscribe anytime.