🔥Stalecollected in 8m

CNCERT Warns OpenClaw Security Risks

CNCERT Warns OpenClaw Security Risks
PostLinkedIn
🔥Read original on 36氪
#security-risks#ai-deployment#vulnerability-alertopenclawopenclaw

💡Urgent OpenClaw risks exposed—secure deployments before breaches hit AI apps.

⚡ 30-Second TL;DR

What Changed

Improper OpenClaw installs caused serious security risks.

Why It Matters

Exposes vulnerabilities in AI agent deployments, potentially leading to exploits; practitioners must harden setups to maintain trust and avoid breaches in production environments.

What To Do Next

Audit your OpenClaw instance today: isolate ports with firewalls and containerize to limit privileges.

Who should care:Developers & AI Engineers

Key Points

  • Improper OpenClaw installs caused serious security risks.
  • Isolate management port; use auth, containers to limit privileges.
  • Avoid plaintext keys in env vars; enable full audit logs.
  • Use only signed plugins from trusted sources; disable auto-updates.
  • Apply security patches and monitor updates promptly.

🧠 Deep Insight

Background and context from public sources — not the original article. 7 sources cited.

🔑 Enhanced Key Takeaways

  • CVE-2026-25253 (CVSS 8.8) enables one-click remote code execution through WebSocket authentication token exfiltration, affecting all OpenClaw versions before 2026.1.29, with over 42,665 publicly exposed instances identified as of late January 2026[2].
  • The ClawHub marketplace contains approximately 800+ malicious skills (~20% of the registry) primarily delivering Atomic macOS Stealer (AMOS) and credential-harvesting payloads, with infostealers like RedLine, Lumma, and Vidar actively targeting OpenClaw configuration files[1][2].
  • OpenClaw's default configuration ships with authentication disabled and stores credentials in plaintext config files, creating a dual-layer vulnerability that enables both unauthorized access and credential compromise at scale[1].
  • Permission misconfiguration risks stem from OpenClaw's autonomous skill-chaining architecture, where a single overprivileged skill can escalate into lateral movement across systems, particularly when deployed with root access and open APIs[5].

🛠️ Technical Deep Dive

Cve_2026_25253_attack_chain

  • Stage 1: Attacker creates malicious webpage containing JavaScript payload
  • Stage 2: Cross-Site WebSocket Hijacking (CSWSH) exploits missing Origin header validation on OpenClaw's WebSocket server (e.g., ws://localhost:18789)
  • Stage 3: Victim's browser becomes bridge into local network; gateway authentication token exfiltrated
  • Stage 4: Attacker gains full administrative control in milliseconds with no prior access required[2]

Exposure_metrics

  • Censys tracked growth from ~1,000 to 21,000+ publicly exposed instances between January 25-31, 2026[2]
  • Bitsight observed 30,000+ instances across broader analysis window[2]
  • Independent researcher Maor Dayan identified 42,665 exposed instances with 5,194 actively verified as vulnerable; 93.4% exhibited authentication bypass conditions[2]

Credential_storage_vulnerabilities

  • API keys, OAuth tokens, and bot credentials stored in plaintext configuration files[1]
  • Infostealers (RedLine, Lumma, Vidar) specifically target OpenClaw file paths alongside traditional browser credential theft[1]
  • Kaspersky documented active harvesting of configuration data[1]

Skill_marketplace_compromise

  • 341 malicious skills initially discovered in ClawHub (12% of registry); updated scans report 800+ malicious skills (~20%)[2]
  • Primary payload: Atomic macOS Stealer (AMOS)[2]
  • Over 400 malicious skills identified across ClawHub and GitHub masquerading as legitimate tools[5]

🔮 Future ImplicationsAI analysis grounded in cited sources

OpenClaw's skill-based architecture will accelerate commoditization of advanced attack infrastructure, enabling novice threat actors to acquire sophisticated lateral movement and persistence capabilities without technical expertise.
The ability to purchase pre-built malicious skills dramatically lowers the barrier to entry for complex cyberattacks, increasing both attack volume and sophistication across the threat landscape[5].
Industry-wide adoption of Zero Trust and microsegmentation will become mandatory rather than optional for organizations deploying autonomous AI agents.
OpenClaw's autonomous skill-chaining and privilege escalation risks demonstrate that traditional perimeter security cannot contain agent-based threats; granular policy enforcement at every access point is now essential[5].
Regulatory frameworks for AI agent security standards will emerge as a direct response to OpenClaw's widespread misconfiguration, similar to how cloud security standards evolved post-S3 bucket exposures.
The scale of exposure (42,665+ instances) and the involvement of national-level security bodies (CNCERT) signals that governments will mandate security baselines for autonomous AI systems[6].

Timeline

2026-01
CVE-2026-25253 discovered by Mav Levin (depthfirst research team); patched in OpenClaw v2026.1.29 on January 30, 2026
2026-01-25
Censys begins tracking publicly exposed OpenClaw instances; ~1,000 instances identified
2026-01-31
Exposure surge documented: 21,000+ publicly exposed instances tracked by Censys; ClawHavoc campaign with 341 malicious skills discovered in ClawHub
2026-02-12
Fortune publishes major security analysis; OpenClaw security concerns become mainstream media focus
2026-02
Kaspersky documents active credential harvesting targeting OpenClaw configuration files via infostealers (RedLine, Lumma, Vidar)
2026-03-10
CNCERT (China's National Internet Emergency Center) issues formal risk alert for OpenClaw security vulnerabilities

📰 Event Coverage

📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: 36氪

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.