🗾Stalecollected in 85m

OpenClaw Flaw Allows Web AI Agent Hijack

OpenClaw Flaw Allows Web AI Agent Hijack
PostLinkedIn
🗾Read original on ITmedia AI+ (日本)
#ai-agent-security#security#gateway-exploitopenclawopenclawoasis-security

💡Web browsing hijacks OpenClaw AI agents—patched fast; secure your deployments now

⚡ 30-Second TL;DR

What Changed

Vulnerability in OpenClaw gateway enables AI agent takeover

Why It Matters

Exposes risks in AI agent deployments using web-integrated gateways. Rapid patching underscores need for vigilant security in open-source AI tools.

What To Do Next

Immediately update OpenClaw to the latest patched version and audit gateway configs.

Who should care:Developers & AI Engineers

Key Points

  • Vulnerability in OpenClaw gateway enables AI agent takeover
  • Exploited via local connections from any website
  • No user interaction beyond web browsing required
  • High severity rating by developers
  • Patched within 24 hours

🧠 Deep Insight

Background and context from public sources — not the original article. 10 sources cited.

🔑 Enhanced Key Takeaways

  • Exploit chain uses malicious JavaScript to open WebSocket to localhost, brute-force gateway password due to absent rate-limiting, gain admin permissions, and auto-register as trusted device.[1][2]
  • Post-hijack, attackers can send messages to AI agent, dump gateway config exposing AI providers and models, enumerate paired devices with IPs, and read logs.[1][2]
  • OpenClaw reached over 100,000 GitHub stars in five days, driving rapid adoption among developers despite vulnerabilities.[3]

🛠️ Technical Deep Dive

  • Vulnerability resides in OpenClaw gateway's WebSocket server on localhost port, lacking rate-limiting for password brute-force from local connections.[1][2]
  • Gateway auto-approves localhost device pairings without user prompts, granting full admin access after authentication.[1][2]
  • Patched versions include 2026.1.20, 2026.1.29, 2026.2.1, 2026.2.2, 2026.2.14, and 2026.2.25+.[1][2]

🔮 Future ImplicationsAI analysis grounded in cited sources

AI agent frameworks will require evolved security models addressing localhost exploits and agentic access.
Broader scrutiny highlights expanded attack surfaces from AI agents' system integrations, necessitating governance beyond traditional vulnerabilities.[1]
Rapid patching will become standard for open-source AI tools amid fast adoption.
OpenClaw fixed high-severity issues within 24 hours, setting expectations as agents proliferate in enterprises.[1][2]

Timeline

2026-01
CVE-2026-25253 one-click RCE disclosed by Mav Levin due to unvalidated WebSocket origin.[5]
2026-02
Oasis Security discovers and discloses ClawJacked vulnerability chain enabling full agent takeover.[2][3]
2026-02
OpenClaw releases patches including v2026.1.29 and v2026.2.25 for ClawJacked and related flaws.[1][2]
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: ITmedia AI+ (日本)

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.